Vulnerability  ·  2026-07-31

Pydantic AI Agent Framework - SSRF Cloud-Metadata Bypass and Cross-Tenant File Disclosure in UI Adapters

VulnerabilityMedium impactGlobalCVE-2026-46678
Pydantic AI is a mainstream Python agent framework; SSRF bypasses against cloud metadata endpoints can lead to IAM credential theft in cloud-hosted agent deployments, and arbitrary file reference via UI adapters can leak sensitive host files to any client able to submit crafted message history.
CVE-2026-46678: when an application opts a URL into force_download='allow-local', the cloud-metadata blocklist can be bypassed by encoding the metadata IP address to evade the filter, enabling SSRF against cloud instance metadata endpoints. CVE-2026-54249: a client submitting message history to a Pydantic AI UI adapter (e.g., Vercel AI adapter) can reference arbitrary files on the application's model-serving host. CVE-2026-65975: UI adapters' sanitize_message function insufficiently sanitizes content, allowing further data exposure.
Pydantic AI 1.56.0-1.98.0 (CVE-2026-46678); 1.65.0-1.105.0 and 2.0.0b1-2.0.0b5 (CVE-2026-54249); 1.88.0-1.107.1 and 2.0.0b1-2.5.0 (CVE-2026-65975)
Upgrade to Pydantic AI 1.99.0+ (CVE-2026-46678 fix) and the versions specified in GHSA-h7p7-w5gc-xj3w and GHSA-jpr8-2v3g-wgf9 for the other two CVEs.
GitHub Release - pydantic-ai v1.99.0GitHub Security Advisory GHSA-h7p7-w5gc-xj3w
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →