crewai-tools is vulnerable to Server-Side Request Forgery (SSRF)
83
High Risk
The validate_url function used by scrape tools and RAG loaders performs a one-shot DNS resolution and private-IP blocklist check, then returns the original URL unchanged. Outbound fetches still follow HTTP redirects automatically, so a URL that passes the check can redirect to an internal address or cloud metadata endpoint and bypass the filter. DNS rebinding can similarly evade the one-shot resolution. The fix validates every redirect target before following it and strips credentials on cross-origin redirects.
You are affected if you are using a version that falls within the vulnerable range and your application uses scrape tools or RAG loaders that fetch remote URLs.
crewai-tools is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 1.15.0.
Upgrade the crewai-tools library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant