THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-37008 (HIGH 8.1) — CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling c

[NVD] CVE-2026-37008 (HIGH 8.1) — CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling c

mednvdPublished 2026-09-13

CVE-2026-37008 CVSS: 8.1 HIGH Published: 2026-09-13T21:17:01.303

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying i

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-37008