Disclosure summary
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address. IPv6Address equality and hashing include the zone identifier, so the blocklist comparison fails even though the network stack ignores the zone on a non-link-local destination and reaches the metadata service, potentially exposing cloud IAM credentials. The opt-in settings are disabled by default, and the issue requires an IPv6-enabled environment. This issue is fixed in versions 1.107.6 and 2.44.0.
Source-reported weakness categories
CWE-918, CWE-1289
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107289
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-vmxc-h2x2-jmf3
Open original source · Updated Oct 08, 2026
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | pydantic-ai | >= 1.56.0, < 1.107.6 | 1.107.6 |
| pip | pydantic-ai | >= 2.0.0b1, < 2.44.0 | 2.44.0 |
| pip | pydantic-ai-slim | >= 1.56.0, < 1.107.6 | 1.107.6 |
| pip | pydantic-ai-slim | >= 2.0.0b1, < 2.44.0 | 2.44.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
PUBLISHED 2026-10-08T12:17:04-04:00
MODIFIED 2026-10-08T16:35:31-04:00
INGESTED 2026-10-10T20:55:03-04:00