LowVulnerability
CVE-2026-107288: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-107288
- Published
- Record updated
Summary
Pydantic AI versions from 1.77.0 up to 1.107.6, and 2.44.0, compare blocked_domains entries against URL hostnames before normalization in the local web_fetch_tool and WebFetch fallback. An attacker-influenced model can use an equivalent spelling, such as an IDNA form, non-ASCII label separator, case variation, or trailing root label, that resolves to a blocked host but fails the string match, so the application fetches that host with its own privileges. allowed_domains fails closed on unmatched spellings, and private-IP and cloud-metadata protections remain effective.
Mitigation
This issue is fixed in versions 1.107.6 and 2.44.0.
Topics
Related items
- LowOAuth grants pile up faster than you can review them. Here's how to keep up.Similar attack · BleepingComputer
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News
- HighCVE-2026-93675: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected…Similar attack · NVD/CVE Database
- HighCVE-2026-105812 and CVE-2026-106032: Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRFSimilar attack · AWS Security Bulletins
- MediumWelcome to the Jungle: What We Found Inside 15,465 Public MCP ServersSimilar attack · The Hacker News