Pydantic AI Multiple Vulnerabilities in Versions 1.56.0-2.0.0b5
Three vulnerabilities discovered in Pydantic AI framework allow attackers to bypass security controls: cloud metadata credential exposure via IPv6-encoded IPs, arbitrary file access through unvalidated UploadedFile references, and execution of unresolved tool calls with attacker-supplied arguments.
Disclosed 29 July 2026 · Record updated 13 September 2026
Impact
Attackers can expose cloud IAM credentials, access arbitrary files in cloud storage accounts, and execute server tools with client-supplied arguments, potentially leading to privilege escalation and data theft.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-46678
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54249
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65975
