Files
crewAI/lib/crewai/tests/cassettes/test_crew_with_delegating_agents.yaml
Rip&Tear fb2323b3de
Some checks failed
CodeQL Advanced / Analyze (actions) (push) Has been cancelled
CodeQL Advanced / Analyze (python) (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Build uv cache / build-cache (3.10) (push) Has been cancelled
Build uv cache / build-cache (3.11) (push) Has been cancelled
Build uv cache / build-cache (3.12) (push) Has been cancelled
Build uv cache / build-cache (3.13) (push) Has been cancelled
Nightly Canary Release / Check for new commits (push) Has been cancelled
Nightly Canary Release / Build nightly packages (push) Has been cancelled
Nightly Canary Release / Publish nightly to PyPI (push) Has been cancelled
Code interpreter sandbox escape (#4791)
* [SECURITY] Fix sandbox escape vulnerability in CodeInterpreterTool (F-001)

This commit addresses a critical security vulnerability where the CodeInterpreterTool
could be exploited via sandbox escape attacks when Docker was unavailable.

Changes:
- Remove insecure fallback to restricted sandbox in run_code_safety()
- Now fails closed with RuntimeError when Docker is unavailable
- Mark run_code_in_restricted_sandbox() as deprecated and insecure
- Add clear security warnings to SandboxPython class documentation
- Update tests to reflect secure-by-default behavior
- Add test demonstrating the sandbox escape vulnerability
- Update README with security requirements and best practices

The previous implementation would fall back to a Python-based 'restricted sandbox'
when Docker was unavailable. However, this sandbox could be easily bypassed using
Python object introspection to recover the original __import__ function, allowing
arbitrary module access and command execution on the host.

The fix enforces Docker as a requirement for safe code execution. Users who cannot
use Docker must explicitly enable unsafe_mode=True, acknowledging the security risks.

Security Impact:
- Prevents RCE via sandbox escape when Docker is unavailable
- Enforces fail-closed security model
- Maintains backward compatibility via unsafe_mode flag

References:
- https://docs.crewai.com/tools/ai-ml/codeinterpretertool

Co-authored-by: Rip&Tear <theCyberTech@users.noreply.github.com>

* Add security fix documentation for F-001

Co-authored-by: Rip&Tear <theCyberTech@users.noreply.github.com>

* Add Slack summary for security fix

Co-authored-by: Rip&Tear <theCyberTech@users.noreply.github.com>

* Delete SECURITY_FIX_F001.md

* Delete SLACK_SUMMARY.md

* chore: regen cassettes

* chore: regen more cassettes

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Rip&Tear <theCyberTech@users.noreply.github.com>
Co-authored-by: Greyson LaLonde <greyson@crewai.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-03-15 13:18:02 +08:00

450 lines
23 KiB
YAML

interactions:
- request:
body: '{"messages":[{"role":"system","content":"You are CEO. You''re an long time
CEO of a content creation agency with a Senior Writer on the team. You''re now
working on a new project and want to make sure the content produced is amazing.\nYour
personal goal is: Make sure the writers in your company produce amazing content."},{"role":"user","content":"\nCurrent
Task: Produce and amazing 1 paragraph draft of an article about AI Agents.\n\nThis
is the expected criteria for your final answer: A 4 paragraph article about
AI.\nyou MUST return the actual complete content as the final answer, not a
summary."}],"model":"gpt-4.1-mini","tool_choice":"auto","tools":[{"type":"function","function":{"name":"delegate_work_to_coworker","description":"Delegate
a specific task to one of the following coworkers: Senior Writer\nThe input
to this tool should be the coworker, the task you want them to do, and ALL necessary
context to execute the task, they know nothing about the task, so share absolutely
everything you know, don''t reference things but instead explain them.","strict":true,"parameters":{"properties":{"task":{"description":"The
task to delegate","title":"Task","type":"string"},"context":{"description":"The
context for the task","title":"Context","type":"string"},"coworker":{"description":"The
role/name of the coworker to delegate to","title":"Coworker","type":"string"}},"required":["task","context","coworker"],"type":"object","additionalProperties":false}}},{"type":"function","function":{"name":"ask_question_to_coworker","description":"Ask
a specific question to one of the following coworkers: Senior Writer\nThe input
to this tool should be the coworker, the question you have for them, and ALL
necessary context to ask the question properly, they know nothing about the
question, so share absolutely everything you know, don''t reference things but
instead explain them.","strict":true,"parameters":{"properties":{"question":{"description":"The
question to ask","title":"Question","type":"string"},"context":{"description":"The
context for the question","title":"Context","type":"string"},"coworker":{"description":"The
role/name of the coworker to ask","title":"Coworker","type":"string"}},"required":["question","context","coworker"],"type":"object","additionalProperties":false}}}]}'
headers:
User-Agent:
- X-USER-AGENT-XXX
accept:
- application/json
accept-encoding:
- ACCEPT-ENCODING-XXX
authorization:
- AUTHORIZATION-XXX
connection:
- keep-alive
content-length:
- '2298'
content-type:
- application/json
host:
- api.openai.com
x-stainless-arch:
- X-STAINLESS-ARCH-XXX
x-stainless-async:
- 'false'
x-stainless-lang:
- python
x-stainless-os:
- X-STAINLESS-OS-XXX
x-stainless-package-version:
- 1.83.0
x-stainless-read-timeout:
- X-STAINLESS-READ-TIMEOUT-XXX
x-stainless-retry-count:
- '0'
x-stainless-runtime:
- CPython
x-stainless-runtime-version:
- 3.13.12
method: POST
uri: https://api.openai.com/v1/chat/completions
response:
body:
string: "{\n \"id\": \"chatcmpl-DJVUF1zvo6c1aeolU4hCgOK2XeUEK\",\n \"object\":
\"chat.completion\",\n \"created\": 1773541639,\n \"model\": \"gpt-4.1-mini-2025-04-14\",\n
\ \"choices\": [\n {\n \"index\": 0,\n \"message\": {\n \"role\":
\"assistant\",\n \"content\": null,\n \"tool_calls\": [\n {\n
\ \"id\": \"call_wi7jZ8PKxWMadJufpDtwfLF3\",\n \"type\":
\"function\",\n \"function\": {\n \"name\": \"delegate_work_to_coworker\",\n
\ \"arguments\": \"{\\\"task\\\":\\\"Produce an amazing 1 paragraph
draft of an article about AI Agents. This paragraph should be engaging, informative,
and provide a clear introduction to the topic of AI Agents, capturing the
readers' interest and setting the stage for a longer article.\\\",\\\"context\\\":\\\"The
article on AI Agents will be a 4 paragraph piece aiming to explain what AI
Agents are, their functionalities, importance, and potential future developments.
The draft paragraph should serve as a compelling introduction that hooks the
audience and introduces the subject matter effectively.\\\",\\\"coworker\\\":\\\"Senior
Writer\\\"}\"\n }\n }\n ],\n \"refusal\":
null,\n \"annotations\": []\n },\n \"logprobs\": null,\n
\ \"finish_reason\": \"tool_calls\"\n }\n ],\n \"usage\": {\n \"prompt_tokens\":
386,\n \"completion_tokens\": 124,\n \"total_tokens\": 510,\n \"prompt_tokens_details\":
{\n \"cached_tokens\": 0,\n \"audio_tokens\": 0\n },\n \"completion_tokens_details\":
{\n \"reasoning_tokens\": 0,\n \"audio_tokens\": 0,\n \"accepted_prediction_tokens\":
0,\n \"rejected_prediction_tokens\": 0\n }\n },\n \"service_tier\":
\"default\",\n \"system_fingerprint\": \"fp_5e793402c9\"\n}\n"
headers:
CF-Cache-Status:
- DYNAMIC
CF-Ray:
- 9dc8140db9f85f83-EWR
Connection:
- keep-alive
Content-Type:
- application/json
Date:
- Sun, 15 Mar 2026 02:27:20 GMT
Server:
- cloudflare
Strict-Transport-Security:
- STS-XXX
Transfer-Encoding:
- chunked
X-Content-Type-Options:
- X-CONTENT-TYPE-XXX
access-control-expose-headers:
- ACCESS-CONTROL-XXX
alt-svc:
- h3=":443"; ma=86400
openai-organization:
- OPENAI-ORG-XXX
openai-processing-ms:
- '1331'
openai-project:
- OPENAI-PROJECT-XXX
openai-version:
- '2020-10-01'
set-cookie:
- SET-COOKIE-XXX
x-openai-proxy-wasm:
- v0.1
x-ratelimit-limit-requests:
- X-RATELIMIT-LIMIT-REQUESTS-XXX
x-ratelimit-limit-tokens:
- X-RATELIMIT-LIMIT-TOKENS-XXX
x-ratelimit-remaining-requests:
- X-RATELIMIT-REMAINING-REQUESTS-XXX
x-ratelimit-remaining-tokens:
- X-RATELIMIT-REMAINING-TOKENS-XXX
x-ratelimit-reset-requests:
- X-RATELIMIT-RESET-REQUESTS-XXX
x-ratelimit-reset-tokens:
- X-RATELIMIT-RESET-TOKENS-XXX
x-request-id:
- X-REQUEST-ID-XXX
status:
code: 200
message: OK
- request:
body: '{"messages":[{"role":"system","content":"You are Senior Writer. You''re
a senior writer, specialized in technology, software engineering, AI and startups.
You work as a freelancer and are now working on writing content for a new customer.\nYour
personal goal is: Write the best content about AI and AI agents."},{"role":"user","content":"\nCurrent
Task: Produce an amazing 1 paragraph draft of an article about AI Agents. This
paragraph should be engaging, informative, and provide a clear introduction
to the topic of AI Agents, capturing the readers'' interest and setting the
stage for a longer article.\n\nThis is the expected criteria for your final
answer: Your best answer to your coworker asking you this, accounting for the
context shared.\nyou MUST return the actual complete content as the final answer,
not a summary.\n\nThis is the context you''re working with:\nThe article on
AI Agents will be a 4 paragraph piece aiming to explain what AI Agents are,
their functionalities, importance, and potential future developments. The draft
paragraph should serve as a compelling introduction that hooks the audience
and introduces the subject matter effectively.\n\nProvide your complete response:"}],"model":"gpt-4.1-mini"}'
headers:
User-Agent:
- X-USER-AGENT-XXX
accept:
- application/json
accept-encoding:
- ACCEPT-ENCODING-XXX
authorization:
- AUTHORIZATION-XXX
connection:
- keep-alive
content-length:
- '1228'
content-type:
- application/json
host:
- api.openai.com
x-stainless-arch:
- X-STAINLESS-ARCH-XXX
x-stainless-async:
- 'false'
x-stainless-lang:
- python
x-stainless-os:
- X-STAINLESS-OS-XXX
x-stainless-package-version:
- 1.83.0
x-stainless-read-timeout:
- X-STAINLESS-READ-TIMEOUT-XXX
x-stainless-retry-count:
- '0'
x-stainless-runtime:
- CPython
x-stainless-runtime-version:
- 3.13.12
method: POST
uri: https://api.openai.com/v1/chat/completions
response:
body:
string: "{\n \"id\": \"chatcmpl-DJVUHEhPlZEKRnV2LXW33Z2y5jZB6\",\n \"object\":
\"chat.completion\",\n \"created\": 1773541641,\n \"model\": \"gpt-4.1-mini-2025-04-14\",\n
\ \"choices\": [\n {\n \"index\": 0,\n \"message\": {\n \"role\":
\"assistant\",\n \"content\": \"In the rapidly evolving landscape of
artificial intelligence, AI agents stand out as transformative entities capable
of perceiving their environment, making decisions, and autonomously executing
tasks to achieve specific goals. Far beyond simple algorithms, these agents
act as intelligent intermediaries that can range from virtual assistants managing
our schedules to complex systems driving autonomous vehicles or optimizing
supply chains. As AI agents increasingly integrate into daily life and business
operations, understanding their core principles and potential impact is essential\u2014not
just for tech enthusiasts but for anyone interested in how intelligent automation
is reshaping our future. This article will explore what AI agents are, how
they function, their growing significance across industries, and the exciting
possibilities they hold on the horizon.\",\n \"refusal\": null,\n \"annotations\":
[]\n },\n \"logprobs\": null,\n \"finish_reason\": \"stop\"\n
\ }\n ],\n \"usage\": {\n \"prompt_tokens\": 222,\n \"completion_tokens\":
137,\n \"total_tokens\": 359,\n \"prompt_tokens_details\": {\n \"cached_tokens\":
0,\n \"audio_tokens\": 0\n },\n \"completion_tokens_details\":
{\n \"reasoning_tokens\": 0,\n \"audio_tokens\": 0,\n \"accepted_prediction_tokens\":
0,\n \"rejected_prediction_tokens\": 0\n }\n },\n \"service_tier\":
\"default\",\n \"system_fingerprint\": \"fp_5e793402c9\"\n}\n"
headers:
CF-Cache-Status:
- DYNAMIC
CF-Ray:
- 9dc814182b1c281b-EWR
Connection:
- keep-alive
Content-Type:
- application/json
Date:
- Sun, 15 Mar 2026 02:27:22 GMT
Server:
- cloudflare
Strict-Transport-Security:
- STS-XXX
Transfer-Encoding:
- chunked
X-Content-Type-Options:
- X-CONTENT-TYPE-XXX
access-control-expose-headers:
- ACCESS-CONTROL-XXX
alt-svc:
- h3=":443"; ma=86400
openai-organization:
- OPENAI-ORG-XXX
openai-processing-ms:
- '1582'
openai-project:
- OPENAI-PROJECT-XXX
openai-version:
- '2020-10-01'
set-cookie:
- SET-COOKIE-XXX
x-openai-proxy-wasm:
- v0.1
x-ratelimit-limit-requests:
- X-RATELIMIT-LIMIT-REQUESTS-XXX
x-ratelimit-limit-tokens:
- X-RATELIMIT-LIMIT-TOKENS-XXX
x-ratelimit-remaining-requests:
- X-RATELIMIT-REMAINING-REQUESTS-XXX
x-ratelimit-remaining-tokens:
- X-RATELIMIT-REMAINING-TOKENS-XXX
x-ratelimit-reset-requests:
- X-RATELIMIT-RESET-REQUESTS-XXX
x-ratelimit-reset-tokens:
- X-RATELIMIT-RESET-TOKENS-XXX
x-request-id:
- X-REQUEST-ID-XXX
status:
code: 200
message: OK
- request:
body: "{\"messages\":[{\"role\":\"system\",\"content\":\"You are CEO. You're an
long time CEO of a content creation agency with a Senior Writer on the team.
You're now working on a new project and want to make sure the content produced
is amazing.\\nYour personal goal is: Make sure the writers in your company produce
amazing content.\"},{\"role\":\"user\",\"content\":\"\\nCurrent Task: Produce
and amazing 1 paragraph draft of an article about AI Agents.\\n\\nThis is the
expected criteria for your final answer: A 4 paragraph article about AI.\\nyou
MUST return the actual complete content as the final answer, not a summary.\"},{\"role\":\"assistant\",\"content\":null,\"tool_calls\":[{\"id\":\"call_wi7jZ8PKxWMadJufpDtwfLF3\",\"type\":\"function\",\"function\":{\"name\":\"delegate_work_to_coworker\",\"arguments\":\"{\\\"task\\\":\\\"Produce
an amazing 1 paragraph draft of an article about AI Agents. This paragraph should
be engaging, informative, and provide a clear introduction to the topic of AI
Agents, capturing the readers' interest and setting the stage for a longer article.\\\",\\\"context\\\":\\\"The
article on AI Agents will be a 4 paragraph piece aiming to explain what AI Agents
are, their functionalities, importance, and potential future developments. The
draft paragraph should serve as a compelling introduction that hooks the audience
and introduces the subject matter effectively.\\\",\\\"coworker\\\":\\\"Senior
Writer\\\"}\"}}]},{\"role\":\"tool\",\"tool_call_id\":\"call_wi7jZ8PKxWMadJufpDtwfLF3\",\"name\":\"delegate_work_to_coworker\",\"content\":\"In
the rapidly evolving landscape of artificial intelligence, AI agents stand out
as transformative entities capable of perceiving their environment, making decisions,
and autonomously executing tasks to achieve specific goals. Far beyond simple
algorithms, these agents act as intelligent intermediaries that can range from
virtual assistants managing our schedules to complex systems driving autonomous
vehicles or optimizing supply chains. As AI agents increasingly integrate into
daily life and business operations, understanding their core principles and
potential impact is essential\u2014not just for tech enthusiasts but for anyone
interested in how intelligent automation is reshaping our future. This article
will explore what AI agents are, how they function, their growing significance
across industries, and the exciting possibilities they hold on the horizon.\"},{\"role\":\"user\",\"content\":\"Analyze
the tool result. If requirements are met, provide the Final Answer. Otherwise,
call the next tool. Deliver only the answer without meta-commentary.\"}],\"model\":\"gpt-4.1-mini\",\"tool_choice\":\"auto\",\"tools\":[{\"type\":\"function\",\"function\":{\"name\":\"delegate_work_to_coworker\",\"description\":\"Delegate
a specific task to one of the following coworkers: Senior Writer\\nThe input
to this tool should be the coworker, the task you want them to do, and ALL necessary
context to execute the task, they know nothing about the task, so share absolutely
everything you know, don't reference things but instead explain them.\",\"strict\":true,\"parameters\":{\"properties\":{\"task\":{\"description\":\"The
task to delegate\",\"title\":\"Task\",\"type\":\"string\"},\"context\":{\"description\":\"The
context for the task\",\"title\":\"Context\",\"type\":\"string\"},\"coworker\":{\"description\":\"The
role/name of the coworker to delegate to\",\"title\":\"Coworker\",\"type\":\"string\"}},\"required\":[\"task\",\"context\",\"coworker\"],\"type\":\"object\",\"additionalProperties\":false}}},{\"type\":\"function\",\"function\":{\"name\":\"ask_question_to_coworker\",\"description\":\"Ask
a specific question to one of the following coworkers: Senior Writer\\nThe input
to this tool should be the coworker, the question you have for them, and ALL
necessary context to ask the question properly, they know nothing about the
question, so share absolutely everything you know, don't reference things but
instead explain them.\",\"strict\":true,\"parameters\":{\"properties\":{\"question\":{\"description\":\"The
question to ask\",\"title\":\"Question\",\"type\":\"string\"},\"context\":{\"description\":\"The
context for the question\",\"title\":\"Context\",\"type\":\"string\"},\"coworker\":{\"description\":\"The
role/name of the coworker to ask\",\"title\":\"Coworker\",\"type\":\"string\"}},\"required\":[\"question\",\"context\",\"coworker\"],\"type\":\"object\",\"additionalProperties\":false}}}]}"
headers:
User-Agent:
- X-USER-AGENT-XXX
accept:
- application/json
accept-encoding:
- ACCEPT-ENCODING-XXX
authorization:
- AUTHORIZATION-XXX
connection:
- keep-alive
content-length:
- '4241'
content-type:
- application/json
cookie:
- COOKIE-XXX
host:
- api.openai.com
x-stainless-arch:
- X-STAINLESS-ARCH-XXX
x-stainless-async:
- 'false'
x-stainless-lang:
- python
x-stainless-os:
- X-STAINLESS-OS-XXX
x-stainless-package-version:
- 1.83.0
x-stainless-read-timeout:
- X-STAINLESS-READ-TIMEOUT-XXX
x-stainless-retry-count:
- '0'
x-stainless-runtime:
- CPython
x-stainless-runtime-version:
- 3.13.12
method: POST
uri: https://api.openai.com/v1/chat/completions
response:
body:
string: "{\n \"id\": \"chatcmpl-DJVUIWVgzE4ZVBGyKaXO2HDAhJvSL\",\n \"object\":
\"chat.completion\",\n \"created\": 1773541642,\n \"model\": \"gpt-4.1-mini-2025-04-14\",\n
\ \"choices\": [\n {\n \"index\": 0,\n \"message\": {\n \"role\":
\"assistant\",\n \"content\": \"AI Agents: Transforming the Future
with Intelligent Automation\\n\\nIn the rapidly evolving landscape of artificial
intelligence, AI agents stand out as transformative entities capable of perceiving
their environment, making decisions, and autonomously executing tasks to achieve
specific goals. Far beyond simple algorithms, these agents act as intelligent
intermediaries that can range from virtual assistants managing our schedules
to complex systems driving autonomous vehicles or optimizing supply chains.
As AI agents increasingly integrate into daily life and business operations,
understanding their core principles and potential impact is essential\u2014not
just for tech enthusiasts but for anyone interested in how intelligent automation
is reshaping our future. This article will explore what AI agents are, how
they function, their growing significance across industries, and the exciting
possibilities they hold on the horizon.\\n\\nAI agents operate by utilizing
a combination of machine learning, natural language processing, and decision-making
algorithms to interpret data, recognize patterns, and perform actions based
on their programming and learning experiences. These intelligent entities
can adapt to new information, improve their performance over time, and interact
with humans or other systems in a meaningful way. From customer service chatbots
that provide personalized support to AI-powered diagnostics in healthcare,
the versatility of AI agents highlights their capacity to enhance efficiency
and innovation across countless fields.\\n\\nThe importance of AI agents extends
beyond automation. They hold the promise of solving complex problems, augmenting
human capabilities, and making real-time decisions in environments where speed
and accuracy are critical. Industries such as finance, logistics, manufacturing,
and entertainment are experiencing disruptive changes driven by AI agents
that help optimize resources, reduce costs, and create new value propositions.
Moreover, ethical considerations and responsible development practices are
crucial to ensure these technologies benefit society while minimizing risks
and biases.\\n\\nLooking ahead, the future of AI agents is brimming with potential.
Advances in explainability, generalization, and collaboration between multiple
agents could lead to even more sophisticated systems capable of tackling challenges
that were once thought to be exclusively human domains. As AI agents continue
to evolve, their integration into everyday life will deepen, transforming
how we work, communicate, and solve problems\u2014ushering in a new era of
intelligent technology that empowers individuals and organizations alike.\",\n
\ \"refusal\": null,\n \"annotations\": []\n },\n \"logprobs\":
null,\n \"finish_reason\": \"stop\"\n }\n ],\n \"usage\": {\n \"prompt_tokens\":
695,\n \"completion_tokens\": 428,\n \"total_tokens\": 1123,\n \"prompt_tokens_details\":
{\n \"cached_tokens\": 0,\n \"audio_tokens\": 0\n },\n \"completion_tokens_details\":
{\n \"reasoning_tokens\": 0,\n \"audio_tokens\": 0,\n \"accepted_prediction_tokens\":
0,\n \"rejected_prediction_tokens\": 0\n }\n },\n \"service_tier\":
\"default\",\n \"system_fingerprint\": \"fp_5e793402c9\"\n}\n"
headers:
CF-Cache-Status:
- DYNAMIC
CF-Ray:
- 9dc814239fb65f83-EWR
Connection:
- keep-alive
Content-Type:
- application/json
Date:
- Sun, 15 Mar 2026 02:27:28 GMT
Server:
- cloudflare
Strict-Transport-Security:
- STS-XXX
Transfer-Encoding:
- chunked
X-Content-Type-Options:
- X-CONTENT-TYPE-XXX
access-control-expose-headers:
- ACCESS-CONTROL-XXX
alt-svc:
- h3=":443"; ma=86400
openai-organization:
- OPENAI-ORG-XXX
openai-processing-ms:
- '4942'
openai-project:
- OPENAI-PROJECT-XXX
openai-version:
- '2020-10-01'
x-openai-proxy-wasm:
- v0.1
x-ratelimit-limit-requests:
- X-RATELIMIT-LIMIT-REQUESTS-XXX
x-ratelimit-limit-tokens:
- X-RATELIMIT-LIMIT-TOKENS-XXX
x-ratelimit-remaining-requests:
- X-RATELIMIT-REMAINING-REQUESTS-XXX
x-ratelimit-remaining-tokens:
- X-RATELIMIT-REMAINING-TOKENS-XXX
x-ratelimit-reset-requests:
- X-RATELIMIT-RESET-REQUESTS-XXX
x-ratelimit-reset-tokens:
- X-RATELIMIT-RESET-TOKENS-XXX
x-request-id:
- X-REQUEST-ID-XXX
status:
code: 200
message: OK
version: 1