VYPR
Vendor

Pydantic AI

Products
3
CVEs
9
Across products
10
Status
Private

Products

3

Recent CVEs

9
  • CVE-2026-25580HigFeb 6, 2026
    risk 0.49cvss 8.6epss 0.01

    Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from…

  • CVE-2026-25640HigFeb 6, 2026
    risk 0.39cvss 7.1epss 0.00

    Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an attacker to serve arbitrary JavaScript in the context of the application by…

  • CVE-2026-54249MedJul 29, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in…

  • CVE-2026-46678MedJul 29, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be…

  • CVE-2026-48782MedJun 17, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous…

  • CVE-2024-3772MedApr 15, 2024
    risk 0.31cvss 5.9epss 0.01

    Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

  • CVE-2026-58203MedJul 6, 2026
    risk 0.27cvss 5.3epss 0.00

    pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. When secrets_nested_subdir=True, a directory entry inside secrets_dir that is a symbolic link pointing…

  • CVE-2021-29510LowMay 13, 2021
    risk 0.15cvss 3.3epss 0.01

    Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU).…

  • CVE-2026-65975MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not including 2.5.0, the UI adapters (AG-UI via Agent.to_ag_ui()/AGUIAdapter, and Vercel AI via…