Skip to content

Hide Navigation Hide TOC

CrewAI RAG URL Validation Bypass SSRF (CVE-2026-2286) - ATR-2026-00547 (208a8914-0d06-5e59-8af2-f9e132ea4d65)

Detects CVE-2026-2286 (CVSS HIGH, CWE-918): CrewAI's RAG (retrieval-augmented generation) URL validator can be bypassed by URL encoding, mixed-case, or alternative representations (decimal IP, hex IP, IPv6 loopback, DNS rebinding shapes) to perform server-side request forgery against internal services on the CrewAI host network. The vulnerability is part of the CERT/CC VU#221883 advisory cluster (four CrewAI CVEs, 2026-03-30). An agent or tool input that passes a crafted RAG source URL causes CrewAI to make internal HTTP requests to metadata services (e.g., AWS IMDS 169.254.169.254), internal APIs, or services on private RFC-1918 ranges — enabling cloud credential theft, internal service enumeration, or lateral movement. Detection covers: (a) RAG source URLs containing SSRF bypass representations of loopback / link-local / private IP ranges; (b) URL-encoded, hex, octal, or decimal IP representations of internal addresses in RAG contexts; (c) CrewAI RAG with cloud metadata endpoint patterns (169.254.169.254); (d) Explicit CVE-2026-2286 / CrewAI SSRF framing.

Cluster A Galaxy A Cluster B Galaxy B Level
CrewAI RAG URL Validation Bypass SSRF (CVE-2026-2286) - ATR-2026-00547 (208a8914-0d06-5e59-8af2-f9e132ea4d65) Agent Threat Rules Proxy - T1090 (731f4f55-b6d0-41d1-a7a9-072a66389aea) Attack Pattern 1
CrewAI RAG URL Validation Bypass SSRF (CVE-2026-2286) - ATR-2026-00547 (208a8914-0d06-5e59-8af2-f9e132ea4d65) Agent Threat Rules Cloud Instance Metadata API - T1552.005 (19bf235b-8620-4997-b5b4-94e0659ed7c3) Attack Pattern 1
CrewAI RAG URL Validation Bypass SSRF (CVE-2026-2286) - ATR-2026-00547 (208a8914-0d06-5e59-8af2-f9e132ea4d65) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) Attack Pattern Cloud Instance Metadata API - T1552.005 (19bf235b-8620-4997-b5b4-94e0659ed7c3) Attack Pattern 2