GHSA-cg7w-rg45-pc59: pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
- Identifiers
- CVE-2026-48782GHSA-cg7w-rg45-pc59
- Published
- Record updated
- Affected
- pydantic-ai-slim >= 1.56.0, < 1.102.0, fixed in 1.102.0
- pydantic-ai >= 1.56.0, < 1.102.0, fixed in 1.102.0
- pydantic-ai >= 2.0.0b1, < 2.0.0b3, fixed in 2.0.0b3
- and 1 more
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
Pydantic AI versions 1.56.0 up to 1.102.0 (and 2.0.0b1 up to 2.0.0b3) contain an incomplete fix for CVE-2026-46678, an SSRF blocklist bypass. When an application sets force_download='allow-local' on a URL that untrusted input can influence, the cloud-metadata blocklist can be evaded by encoding the metadata IP in IPv6 transition forms the previous fix did not decode, exposing cloud IAM short-term credentials. Exploitation requires NAT64- or ISATAP-routing networks, and the advisory rates it MEDIUM (CVSS 6.8).
Mitigation
Upgrade to 1.102.0 or later, or 2.0.0b3 or later on the 2.0 pre-release line. The cloud-metadata and private-IP blocklists now decode the embedded IPv4 of every standardized IPv6 transition form before evaluating it, including IPv4-mapped, IPv4-compatible, 6to4, and NAT64 across all prefix lengths.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- pydantic-aiPyPILLM dependency since 2024-05-20 · 4 tracked dependents
- pydantic-ai-slimPyPILLM dependency since 2024-11-25 · 7 tracked dependents
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading