CVE-2026-54249Disclosure(pydantic / pydantic_ai)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pydantic pydantic_ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model-provider or cloud-storage account. While file URL parts are validated against a scheme allowlist, UploadedFile references — which point to a file by provider file ID or cloud-storage URI (e.g. s3://…, gs://…) — were forwarded without validation. Because the provider resolves an UploadedFile using the server-side identity (IAM role, service account, or provider API key) rather than the client's, an attacker can craft message history to make the server read objects from its own account or other tenants, given a referenceable identifier. Exploitation requires a valid file identifier, which is not always unguessable depending on how the application names objects. This issue has been fixed in versions 1.106.0 and 2.0.0b6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pydantic_ai

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
pydantic_ai

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-13: 1Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-14: 108-1308-14
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-131
Disclosure1
2026-08-141
Patch1
Full discourse2 posts
  • HOL@HashgraphOnline
    Patch

    pydantic-ai versions 1.65.0 through 1.105.x have a server-side file access flaw (CVE-2026-54249). A client that can send message history to a Pydantic AI UI adapter can reference arbitrary files that get fetched using the server's own model-provider or cloud credentials. The URL parts are never validated, so the server forwards them upstream and the file content comes back through the model response. Affected: pydantic-ai and pydantic-ai-slim (pip). Patch in 1.106.0. 2.0 betas before b6 also affected. https://hol.org/guard/security/cves/CVE-2026-54249-pydantic-ai-unvalidated-uploadedfile-references

    Post summary

    The post reports a server‑side file access flaw in pydantic‑ai, discloses that a patch is available in version 1.106.0, and provides technical details on the vulnerability.

    120701.1K
    19.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Pydantic #AI, Server-Side Request Forgery (SSRF), #CVE-2026-54249 (Medium) -DC-Aug2026-1486 https://dailycve.com/pydantic-ai-server-side-request-forgery-ssrf-cve-2026-54249-medium-dc-aug2026-1486/

    Post summary

    A new CVE (CVE-2026-54249) affecting Pydantic AI has been disclosed as a medium‑severity SSRF vulnerability, with basic details shared through a DailyCVE link.

    0000056
    226 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Apppydanticpydantic_ai-python-
Apppydanticpydantic_ai2.0.0python-
Apppydanticpydantic_ai2.0.0python-
Apppydanticpydantic_ai2.0.0python-
Apppydanticpydantic_ai2.0.0python-
Apppydanticpydantic_ai2.0.0python-

Explore more