Vulnerability in Pydantic AI Framework Affecting Generative AI Applications
CVE-2026-65975
6.5MEDIUM
What is CVE-2026-65975?
A vulnerability in the Pydantic AI framework allows remote clients to execute non-approved tools with unvalidated client-supplied arguments due to insufficient sanitization of unresolved tool calls. This security flaw arises from an improper handling of message sanitization, which fails to effectively prevent the dispatch of potentially harmful commands. As a result, the integrity and security of applications built on this framework could be severely compromised, emphasizing the importance of updating to patched versions 1.107.1 and 2.5.0 to mitigate potential risks.
Affected Version(s)
pydantic-ai >= 1.88.0, < 1.107.1 < 1.88.0, 1.107.1
pydantic-ai >= 2.0.0b1, < 2.5.0 < 2.0.0b1, 2.5.0
pydantic-ai-slim >= 1.88.0, < 1.107.1 < 1.88.0, 1.107.1
