VulnWatch VulnWatch
← Back to dashboard
Unknown nvd · CVE-2026-37009

CVE-2026-37009: A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL

Published Aug 27, 2026

A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument.

Affected AI Products

crewai
Get the weekly digest. Every Monday: top AI security stories of the week. Free.