CVE-2026-107289
Last modified
CVE-2026-107289 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address.
Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address. IPv6Address equality and hashing include the zone identifier, so the blocklist comparison fails even though the network stack ignores the zone on a non-link-local destination and reaches the metadata service, potentially exposing cloud IAM credentials. The opt-in settings are disabled by default, and the issue requires an IPv6-enabled environment. This issue is fixed in versions 1.107.6 and 2.44.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| pydantic | pydantic-ai | >= 1.56.0, < 1.107.6; >= 2.0.0b1, < 2.44.0 |
| pydantic | pydantic-ai-slim | >= 1.56.0, < 1.107.6; >= 2.0.0b1, < 2.44.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-107289?
How severe is CVE-2026-107289?
How do I fix CVE-2026-107289?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107283The AsyncHttpClient (AHC) library allows Java applications t…3.7
- CVE-2026-107284The AsyncHttpClient (AHC) library allows Java applications t…3.7
- CVE-2026-107285The AsyncHttpClient (AHC) library allows Java applications t…5.9
- CVE-2026-107286Pydantic AI is a Python agent framework for building applica…7.5
- CVE-2026-107287Pydantic AI is a Python agent framework for building applica…6.5
- CVE-2026-107288Pydantic AI is a Python agent framework for building applica…3.7
- CVE-2026-10729An HTML injection vulnerability in the notification email fo…1.2
- CVE-2026-107290Pydantic AI is a Python agent framework for building applica…6.5
- CVE-2026-107291Pydantic AI is a Python agent framework for building applica…2.3
- CVE-2026-107292Pydantic AI is a Python agent framework for building applica…6.4
- CVE-2026-107293Pydantic AI is a Python agent framework for building applica…2.3
- CVE-2026-107294Pydantic AI is a Python agent framework for building applica…6.5
Are you affected by CVE-2026-107289?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
