Skip to content
MediumVulnerability

GHSA-vmxc-h2x2-jmf3: Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers

Published
Record updated
View JSON

Summary

Pydantic AI's cloud-metadata blocklist can be bypassed by appending an IPv6 zone identifier, such as fd00:ec2::254%251, to a metadata address when local network access is enabled via force_download='allow-local' or web_fetch_tool(allow_local_urls=True). The host ignores the zone identifier on non-link-local destinations, so requests reach the metadata endpoint and can expose cloud IAM short-term credentials. This is an incomplete fix of GHSA-cqp8-fcvh-x7r3 / CVE-2026-46678 and GHSA-cg7w-rg45-pc59 / CVE-2026-48782, both follow-ups to CVE-2026-25580.

Mitigation

Upgrade to a patched version. The cloud-metadata and private-IP checks now drop an IPv6 zone identifier before evaluating the address. Workaround for unpatched versions: avoid local network access on URLs that untrusted input could influence, or reject URL hosts containing '%' before constructing the FileUrl or configuring the tool.