Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Pydantic AI Multiple Vulnerabilities in Versions 1.56.0-2.0.0b5

Three vulnerabilities discovered in Pydantic AI framework allow attackers to bypass security controls: cloud metadata credential exposure via IPv6-encoded IPs, arbitrary file access through unvalidated UploadedFile references, and execution of unresolved tool calls with attacker-supplied arguments.

Disclosed 29 July 2026 · Record updated 13 September 2026

Impact

Attackers can expose cloud IAM credentials, access arbitrary files in cloud storage accounts, and execute server tools with client-supplied arguments, potentially leading to privilege escalation and data theft.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-46678
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54249
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65975