Agent Security
CrewAI Sandbox Escape: Four CVEs That Chain Through Prompt Injection
Cyata disclosed four CrewAI vulnerabilities in early 2026 that chain through prompt injection to RCE, SSRF, and arbitrary file read. The Docker-fallback design pattern is the root cause.
Apr 8, 20266 min read