CVE-2026-2285: exploitation status and patch state
CVE-2026-2285 · EPSS 1%
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.
Is CVE-2026-2285 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.