{"data":{"id":"58dc5497-fc53-403d-9a2b-3ec01674c56b","title":"GHSA-vmxc-h2x2-jmf3: Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers","summary":"Pydantic AI's cloud-metadata blocklist can be bypassed by appending an IPv6 zone identifier, such as fd00:ec2::254%251, to a metadata address when local network access is enabled via force_download='allow-local' or web_fetch_tool(allow_local_urls=True). The host ignores the zone identifier on non-link-local destinations, so requests reach the metadata endpoint and can expose cloud IAM short-term credentials. This is an incomplete fix of GHSA-cqp8-fcvh-x7r3 / CVE-2026-46678 and GHSA-cg7w-rg45-pc59 / CVE-2026-48782, both follow-ups to CVE-2026-25580.","solution":"Upgrade to a patched version. The cloud-metadata and private-IP checks now drop an IPv6 zone identifier before evaluating the address. Workaround for unpatched versions: avoid local network access on URLs that untrusted input could influence, or reject URL hosts containing '%' before constructing the FileUrl or configuring the tool.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-vmxc-h2x2-jmf3","publishedAt":"2026-10-08T16:48:06.000Z","cveId":"CVE-2026-107289","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["pydantic-ai-slim@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai-slim@>= 1.56.0, < 1.107.6 (fixed: 1.107.6)","pydantic-ai@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai@>= 1.56.0, < 1.107.6 (fixed: 1.107.6)"],"affectedPackageNames":["pydantic-ai-slim","pydantic-ai"],"affectedVendors":[],"affectedVendorsRaw":["Pydantic AI"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00328,"epssCheckedAt":"2026-10-10T06:41:57.681Z","kevDateAdded":null,"advisoryAliases":["GHSA-vmxc-h2x2-jmf3"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T16:48:06.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}