Network Access Vulnerability in Pydantic AI Framework by Pydantic
CVE-2026-107289
What is CVE-2026-107289?
Pydantic AI, a Python agent framework, has a network access vulnerability in versions 1.56.0 to 1.107.6 and 2.44.0. Applications utilizing attacker-influenced URLs enabled with 'allow-local'/web_fetch_tool can bypass the cloud-metadata blocklist. This occurs by appending an IPv6 zone identifier, leading to successful comparisons despite the network stack ignoring the zone in a non-link-local destination. Consequently, this issue could allow unauthorized access to sensitive cloud IAM credentials. The vulnerability primarily requires an IPv6-enabled environment, but opt-in settings for this risk are disabled by default. A fix is available in versions 1.107.6 and 2.44.0.
Affected Version(s)
pydantic-ai >= 1.56.0, < 1.107.6 < 1.56.0, 1.107.6
pydantic-ai >= 2.0.0b1, < 2.44.0 < 2.0.0b1, 2.44.0
pydantic-ai-slim >= 1.56.0, < 1.107.6 < 1.56.0, 1.107.6
