File Reference Vulnerability in Pydantic AI Framework by Pydantic
CVE-2026-54249
What is CVE-2026-54249?
In Pydantic AI versions ranging from 1.65.0 to 1.105.0 and 2.0.0b1 to 2.0.0b5, an attacker can exploit a flaw where client-submitted message history references UploadedFile objects without sufficient validation. This allows malicious users to access arbitrary files within the application's infrastructure, including potentially sensitive data stored under the same cloud-storage infrastructure. Valid exploitation requires knowledge of specific file identifiers, which may not always be secure or unguessable. This vulnerability poses a significant risk to data integrity and confidentiality, emphasizing the need for timely updates to version 1.106.0 or 2.0.0b6, where the issue has been resolved.
Affected Version(s)
pydantic-ai >= 1.65.0, < 1.106.0 < 1.65.0, 1.106.0
pydantic-ai >= 2.0.0b1, < 2.0.0b6 < 2.0.0b1, 2.0.0b6
pydantic-ai-slim >= 2.0.0b1, < 2.0.0b6 < 2.0.0b1, 2.0.0b6
