Pydantic AI 是一个用于构建生成式 AI 应用程序和工作流的 Python 智能体框架。在版本 1.56.0 至 1.107.6(不含 1.107.6)以及 2.44.0 之前,若应用程序通过 FileUrl(使用 force_download='allow-local' 参数)或 web_fetch_tool(使用 allow_local_urls=True 参数)显式允许攻击者控制的 URL 访问本地网络,则攻击者可通过将 IPv6 区域标识符(zone identifier)附加到 IPv6 元数据
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pydantic | pydantic-ai | >= 1.56.0, < 1.107.6 | - |
|
| pydantic | pydantic-ai-slim | >= 1.56.0, < 1.107.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107295 | 7.6 HIGH | `pydantic-ai-slim` web UI `/api/chat` accepts browser-simple cross-origin requests that ca |
| CVE-2026-107286 | 7.5 HIGH | Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends e |
| CVE-2026-107287 | 6.5 MEDIUM | Pydantic AI: Excessive resource use when local web fetching converts nested HTML |
| CVE-2026-107290 | 6.5 MEDIUM | Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` |
| CVE-2026-107294 | 6.5 MEDIUM | Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl |
| CVE-2026-107292 | 6.4 MEDIUM | Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not v |
| CVE-2026-107288 | 3.7 LOW | Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes |
| CVE-2026-107291 | 2.3 LOW | Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans in |
| CVE-2026-107293 | 2.3 LOW | Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `incl |
No comments yet