← Voltar à pesquisa de CVEs

CVE-2026-54249

Pydantic AI

Descrição

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application-s model-provider or cloud-storage account. While file URL parts are validated against a scheme allowlist, UploadedFile references — which point to a file by provider file ID or cloud-storage URI (e.g. s3://…, gs://…) — were forwarded without validation. Because the provider resolves an UploadedFile using the server-side identity (IAM role, service account, or provider API key) rather than the client-s, an attacker can craft message history to make the server read objects from its own account or other tenants, given a referenceable identifier. Exploitation requires a valid file identifier, which is not always unguessable depending on how the application names objects. This issue has been fixed in versions 1.106.0 and 2.0.0b6.

CVSS 6.8EPSS 0.197%Risco 0.69
Ver fonte
Publicação
2026-07-29 21:17:47
Versões afetadas
>=1.65.0,<1.106.0,>=2.0.0b1,<2.0.0b6
Tipo
Software crítico
Última alteração
2026-08-04 13:22:03
Vetor
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N