AI Security · Misconfiguration

CrewAI Code Interpreter Flaws Let Agents Escape Sandboxes

Enabled Code Interpreter lets prompt injection escape sandbox, execute code. Researchers found four linked CrewAI flaws: a Docker fallback to unsafe SandboxPython that permits arbitrary C-level calls, an SSRF in RAG search tools, a runtime Docker-check that triggers the unsafe fallback, and a JSON loader that reads arbitrary local files. An attacker who can influence an agent with the Code Interpreter enabled or a code-execution flag set can chain these bugs to escape the sandbox and run code or read files on the host.

1 source · Mar 31

CVE-2026-2287

NVD KEV

EPSS 0.7% (52nd percentile).

CVE-2026-2285

NVD KEV

EPSS 0.6% (44th percentile).

CVE-2026-2286

NVD KEV

EPSS 0.5% (37th percentile).

CVE-2026-2275

NVD KEV

CVSS 9.6 CRITICAL: the CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through… EPSS 0.4% (35th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-04-01

Every edition of this story: CrewAI Code Interpreter Flaws Let Agents Escape Sandboxes

More from today