Security: pydantic/pydantic-ai
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header, so DNS rebinding can reach it from a website the developer visitsGHSA-q2xc-rrxj-58x9 published
Aug 14, 2026 by dsfacciniModerate -
OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`GHSA-3gh4-cghq-f8v4 published
Aug 12, 2026 by dsfacciniLow -
Unbounded memory use when downloading remote content via web_fetch or FileUrlGHSA-v2xh-2vp8-57h8 published
Aug 8, 2026 by dsfacciniModerate -
Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpointGHSA-h4xc-3qfq-jf93 published
Aug 12, 2026 by dsfacciniHigh -
UI adapters (AG-UI, Vercel AI): a dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`GHSA-jpr8-2v3g-wgf9 published
Jul 11, 2026 by dsfacciniModerate -
VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injectionGHSA-h7p7-w5gc-xj3w published
Jun 10, 2026 by dsfacciniModerate -
SSRF cloud-metadata blocklist bypass via additional IPv6 transition formsGHSA-cg7w-rg45-pc59 published
May 23, 2026 by DouweMModerate -
SSRF cloud-metadata blocklist bypass via IPv6-encoded address formsGHSA-cqp8-fcvh-x7r3 published
May 20, 2026 by DouweMModerate -
Stored XSS via Path Traversal in Web UI CDN URLGHSA-wjp5-868j-wqv7 published
Feb 6, 2026 by DouweMHigh -
Server-Side Request Forgery (SSRF) in URL Download HandlingGHSA-2jrp-274c-jhv3 published
Feb 6, 2026 by DouweMHigh