CVE-2026-54249: CWE-918: Server-Side Request Forgery (SSRF) in pydantic pydantic-ai
CVE-2026-54249 is a Server-Side Request Forgery (SSRF) vulnerability in pydantic-ai that allows a client submitting message history to reference arbitrary files accessible by the server's credentials. This occurs because UploadedFile references are forwarded without proper validation, enabling unauthorized file access. The issue affects versions from 1.65.0 up to and including 1.105.0. A patch is available in versions 1.106.0 and 2.0.0b6 that adds validation for UploadedFile references. If upgrading is not possible, users should avoid passing untrusted message history or strip UploadedFile parts before processing.
AI Analysis
Technical Summary
The vulnerability in pydantic-ai arises from improper validation of UploadedFile references in client-submitted message history forwarded to model providers. While file URLs are validated against a scheme allowlist, UploadedFile references (e.g., provider file IDs or cloud storage URIs like s3:// or gs://) are not validated, allowing an attacker to cause the server to fetch arbitrary files using its own credentials. This can lead to unauthorized reading of files belonging to the server's account or other tenants if valid file identifiers are guessed or known. The vulnerability affects versions >=1.65.0 <=1.105.0. Patches in 1.106.0 and 2.0.0b6 introduce validation for these references to prevent exploitation.
Potential Impact
An attacker can exploit this vulnerability to read files that the server has access to but the attacker should not, by submitting crafted message history containing UploadedFile references. This can lead to unauthorized disclosure of sensitive data stored in the server's model-provider or cloud-storage accounts. The CVSS score is 6.8 (medium severity), reflecting high confidentiality impact but no integrity or availability impact. Exploitation requires knowledge or guessability of valid file identifiers.
Mitigation Recommendations
A fix is available in pydantic-ai versions 1.106.0 and 2.0.0b6, which validate UploadedFile references similarly to file URLs. Users should upgrade to these versions to remediate the vulnerability. If upgrading is not feasible, users should avoid passing untrusted client-submitted message history to the agent or strip UploadedFile parts from incoming messages before processing to prevent exploitation.
CVE-2026-54249: CWE-918: Server-Side Request Forgery (SSRF) in pydantic pydantic-ai
Description
CVE-2026-54249 is a Server-Side Request Forgery (SSRF) vulnerability in pydantic-ai that allows a client submitting message history to reference arbitrary files accessible by the server's credentials. This occurs because UploadedFile references are forwarded without proper validation, enabling unauthorized file access. The issue affects versions from 1.65.0 up to and including 1.105.0. A patch is available in versions 1.106.0 and 2.0.0b6 that adds validation for UploadedFile references. If upgrading is not possible, users should avoid passing untrusted message history or strip UploadedFile parts before processing.
CVSS v3.1
Score 6.8medium
Affected software
pydantic
pydantic-ai
pydantic
pydantic-ai-slim
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in pydantic-ai arises from improper validation of UploadedFile references in client-submitted message history forwarded to model providers. While file URLs are validated against a scheme allowlist, UploadedFile references (e.g., provider file IDs or cloud storage URIs like s3:// or gs://) are not validated, allowing an attacker to cause the server to fetch arbitrary files using its own credentials. This can lead to unauthorized reading of files belonging to the server's account or other tenants if valid file identifiers are guessed or known. The vulnerability affects versions >=1.65.0 <=1.105.0. Patches in 1.106.0 and 2.0.0b6 introduce validation for these references to prevent exploitation.
Potential Impact
An attacker can exploit this vulnerability to read files that the server has access to but the attacker should not, by submitting crafted message history containing UploadedFile references. This can lead to unauthorized disclosure of sensitive data stored in the server's model-provider or cloud-storage accounts. The CVSS score is 6.8 (medium severity), reflecting high confidentiality impact but no integrity or availability impact. Exploitation requires knowledge or guessability of valid file identifiers.
Mitigation Recommendations
A fix is available in pydantic-ai versions 1.106.0 and 2.0.0b6, which validate UploadedFile references similarly to file URLs. Users should upgrade to these versions to remediate the vulnerability. If upgrading is not feasible, users should avoid passing untrusted client-submitted message history to the agent or strip UploadedFile parts from incoming messages before processing to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-12T16:25:43.085Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6a6a68269c2644c7f80739e2
Added to database: 07/29/2026, 20:52:54 UTC
Last enriched: 08/13/2026, 18:11:09 UTC
Last updated: 09/11/2026, 19:31:56 UTC
Views: 91
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.