Pydantic pydantic-ai是Pydantic组织开源的一个用于构建生产级应用程序和工作流的生成式AI框架。 pydantic-ai 1.65.0至1.105.0版本和2.0.0b1至2.0.0b5版本存在服务端请求伪造漏洞,该漏洞源于UploadedFile引用未经验证,可能导致攻击者构造消息历史使服务器读取自身账户或其他租户的对象。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pydantic | pydantic-ai | >= 1.65.0, < 1.106.0 |
affected |
>= 2.0.0b1, < 2.0.0b6 |
affected | ||
| pydantic | pydantic-ai-slim | >= 2.0.0b1, < 2.0.0b6 |
affected |
>= 1.65.0, < 1.106.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pydantic | pydantic-ai | >= 1.65.0, < 1.106.0 | - |
|
| pydantic | pydantic-ai-slim | >= 2.0.0b1, < 2.0.0b6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46678 | 6.8 MEDIUM | Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of |
| CVE-2026-65975 | 6.5 MEDIUM | Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a traili |
No comments yet