
pydantic-ai versions 1.65.0 through 1.105.x have a server-side file access flaw (CVE-2026-54249). A client that can send message history to a Pydantic AI UI adapter can reference arbitrary files that get fetched using the server's own model-provider or cloud credentials. The URL parts are never validated, so the server forwards them upstream and the file content comes back through the model response. Affected: pydantic-ai and pydantic-ai-slim (pip). Patch in 1.106.0. 2.0 betas before b6 also affected. https://hol.org/guard/security/cves/CVE-2026-54249-pydantic-ai-unvalidated-uploadedfile-references
Post summary
The post reports a server‑side file access flaw in pydantic‑ai, discloses that a patch is available in version 1.106.0, and provides technical details on the vulnerability.

