GHSA-vmxc-h2x2-jmf3: Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers
- Identifiers
- CVE-2026-107289GHSA-vmxc-h2x2-jmf3
- Published
- Record updated
Summary
Pydantic AI's cloud-metadata blocklist can be bypassed by appending an IPv6 zone identifier, such as fd00:ec2::254%251, to a metadata address when local network access is enabled via force_download='allow-local' or web_fetch_tool(allow_local_urls=True). The host ignores the zone identifier on non-link-local destinations, so requests reach the metadata endpoint and can expose cloud IAM short-term credentials. This is an incomplete fix of GHSA-cqp8-fcvh-x7r3 / CVE-2026-46678 and GHSA-cg7w-rg45-pc59 / CVE-2026-48782, both follow-ups to CVE-2026-25580.
Mitigation
Upgrade to a patched version. The cloud-metadata and private-IP checks now drop an IPv6 zone identifier before evaluating the address. Workaround for unpatched versions: avoid local network access on URLs that untrusted input could influence, or reject URL hosts containing '%' before constructing the FileUrl or configuring the tool.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database