CVE-2026-107289 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.
Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address. IPv6Address equality and hashing include the zone identifier, so the blocklist comparison fails even though the network stack ignores the zone on a non-link-local destination and reaches the metadata service, potentially exposing cloud IAM credentials. The opt-in settings are disabled by default, and the issue requires an IPv6-enabled environment. This issue is fixed in versions 1.107.6 and 2.44.0.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Changed
Scope
C
High
Confidentiality
I
None
Integrity
A
None
Availability
Affected
- Vendor
- PyPI
- Product
- pydantic-ai
Versions
- pkg:pypi/pydantic-ai >= 1.56.0, < 1.107.6
- pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.44.0
- pkg:pypi/pydantic-ai-slim >= 1.56.0, < 1.107.6
- pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.44.0
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/pydantic/pydantic-ai/commit/02157e1b87bd45d3f2e111ce07afdf89f9fb0e5b
- advisory[email protected]https://github.com/pydantic/pydantic-ai/commit/4da70591460f51a8c4f128eaeef70a33340dbd55
- advisory[email protected]https://github.com/pydantic/pydantic-ai/pull/8401
- advisory[email protected]https://github.com/pydantic/pydantic-ai/pull/8402
- advisory[email protected]https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6
- advisory[email protected]https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0
- advisory[email protected]https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-vmxc-h2x2-jmf3
- advisoryOSV GHSA-vmxc-h2x2-jmf3https://osv.dev/vulnerability/GHSA-vmxc-h2x2-jmf3
- vendorOSV packagehttps://github.com/pydantic/pydantic-ai
Related threats
same CWE or vendorCVE-2026-107781 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerabili…
CVE-2026-107781 · 2h ago
CVE-2026-107394 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.
CVE-2026-107394 · 3h ago
PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-60086 · 4h ago
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433 · 4h ago
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-61435 · 4h ago
CVE-2026-107698 — FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that fol…
CVE-2026-107698 · 5h ago