crewai-tools is vulnerable to Information Disclosure
59
Medium Risk
The RagTool adapter field held live runtime objects that were included when the tool was JSON-serialized during agent tool-calling or checkpoint flows. That could expose internal adapter state to LLM-visible outputs, logs, or persisted checkpoints. The fix serializes the adapter as null and rebuilds a fresh adapter from the tool configuration after deserialization.
You are affected if you are using a version that falls within the vulnerable range.
crewai-tools is vulnerable to Information Disclosure in versions 1.0.0 - 1.14.5.
Upgrade the crewai-tools library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant