VendorsPydanticpydantic_aiany version
Vulnerabilities

Pydantic AI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-25580
Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling
Published 2026-02-06 · Modified
8.6EPSS 0.007
CVE-2026-25640
Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL
Published 2026-02-06 · Modified
7.1EPSS 0.004
CVE-2026-48782
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
Published 2026-06-16 · Analyzed
6.8EPSS 0.004
CVE-2026-46678
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
Published 2026-07-29 · Analyzed
6.8EPSS 0.004
CVE-2026-54249
VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injection
Published 2026-07-29 · Analyzed
6.8EPSS 0.003
CVE-2026-65975
Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`
Published 2026-07-29 · Analyzed
6.5EPSS 0.003