Network Access Vulnerability in Pydantic AI Framework by Pydantic
CVE-2026-107289

6.8MEDIUM

Key Information:

Vendor

Pydantic

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107289?

Pydantic AI, a Python agent framework, has a network access vulnerability in versions 1.56.0 to 1.107.6 and 2.44.0. Applications utilizing attacker-influenced URLs enabled with 'allow-local'/web_fetch_tool can bypass the cloud-metadata blocklist. This occurs by appending an IPv6 zone identifier, leading to successful comparisons despite the network stack ignoring the zone in a non-link-local destination. Consequently, this issue could allow unauthorized access to sensitive cloud IAM credentials. The vulnerability primarily requires an IPv6-enabled environment, but opt-in settings for this risk are disabled by default. A fix is available in versions 1.107.6 and 2.44.0.

Affected Version(s)

pydantic-ai >= 1.56.0, < 1.107.6 < 1.56.0, 1.107.6

pydantic-ai >= 2.0.0b1, < 2.44.0 < 2.0.0b1, 2.44.0

pydantic-ai-slim >= 1.56.0, < 1.107.6 < 1.56.0, 1.107.6

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.