Pydantic pydantic-ai是Pydantic组织开源的一个用于构建生产级应用程序和工作流的生成式AI框架。 pydantic-ai 1.88.0版本至1.107.1之前版本和2.0.0b1版本至2.5.0之前版本存在授权问题漏洞,该漏洞源于UI适配器中sanitize_messages清理逻辑存在缺陷,可能导致远程客户端绕过安全检查,使非审批服务器工具以客户端提供的参数执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pydantic | pydantic-ai | >= 1.88.0, < 1.107.1 |
affected |
>= 2.0.0b1, < 2.5.0 |
affected | ||
| pydantic | pydantic-ai-slim | >= 1.88.0, < 1.107.1 |
affected |
>= 2.0.0b1, < 2.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pydantic | pydantic-ai | >= 1.88.0, < 1.107.1 | - |
|
| pydantic | pydantic-ai-slim | >= 1.88.0, < 1.107.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46678 | 6.8 MEDIUM | Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of |
| CVE-2026-54249 | 6.8 MEDIUM | VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — |
No comments yet