CVE-2026-54249
Last modified
CVE-2026-54249 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model-provider or cloud-storage account. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model-provider or cloud-storage account. While file URL parts are validated against a scheme allowlist, UploadedFile references — which point to a file by provider file ID or cloud-storage URI (e.g. s3://…, gs://…) — were forwarded without validation. Because the provider resolves an UploadedFile using the server-side identity (IAM role, service account, or provider API key) rather than the client's, an attacker can craft message history to make the server read objects from its own account or other tenants, given a referenceable identifier. Exploitation requires a valid file identifier, which is not always unguessable depending on how the application names objects. This issue has been fixed in versions 1.106.0 and 2.0.0b6.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Pydantic | Pydantic Ai | >= 1.65.0, < 1.105.0 | — |
| Pydantic | Pydantic Ai | 2.0.0 | Beta1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-54249?
How severe is CVE-2026-54249?
How do I fix CVE-2026-54249?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54243Statamic is a Laravel and Git powered content management sys…6.1
- CVE-2026-54244Statamic is a Laravel and Git powered content management sys…3.5
- CVE-2026-54245Fleet is an open-source device management platform built on …7.6
- CVE-2026-54246Skipper is an HTTP router and reverse proxy for service comp…5.7
- CVE-2026-54247Skipper is an HTTP router and reverse proxy for service comp…4.3
- CVE-2026-54248Doco-CD is a GitOps continuous delivery tool that automatica…6.5
- CVE-2026-5425The Widgets for Social Photo Feed plugin for WordPress is vu…7.2
- CVE-2026-54250K3s is a fully conformant production-ready Kubernetes distri…5.8
- CVE-2026-54251netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP…8.7
- CVE-2026-54253TS3 Manager is modern web interface for maintaining Teamspea…8.2
- CVE-2026-54254Cyberdrop-DL is a bulk asynchronous downloader for multiple …5.9
- CVE-2026-54256Winter CMS is a content management system built on the Larav…5.4
Are you affected by CVE-2026-54249?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
