Local Web Fetching Vulnerability in Pydantic AI Framework
CVE-2026-107288
What is CVE-2026-107288?
A local web fetching vulnerability exists in the Pydantic AI framework due to improper validation of domain entries in the web_fetch_tool component. Attackers can exploit this flaw by manipulating an application to fetch content from a blocked domain using misleading variations of the URL. Even when protected by domain restrictions, the application’s retrieval mechanisms can be bypassed when the input is normalized incorrectly. While protections against private IPs and cloud metadata are intact, it is crucial to update to versions 1.107.6 or 2.44.0, which address this security issue.
Affected Version(s)
pydantic-ai >= 1.77.0, < 1.107.6 < 1.77.0, 1.107.6
pydantic-ai >= 2.0.0b1, < 2.44.0 < 2.0.0b1, 2.44.0
pydantic-ai-slim >= 1.77.0, < 1.107.6 < 1.77.0, 1.107.6
