THREAT OPS › Threat News › [NVD] CVE-2026-37008 (HIGH 8.1) — CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling c
[NVD] CVE-2026-37008 (HIGH 8.1) — CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling c
CVE-2026-37008 CVSS: 8.1 HIGH Published: 2026-09-13T21:17:01.303
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying i
Indicators of compromise
- CVE-2026-37008cve
- CVE-2026-2275cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-37008