The CVE record describes a local file read vulnerability in pydantic-settings versions from 2.12.0 to 2.14.2. An attacker with influence over the configured secrets directory can read files outside the directory, bypassing the documented size protection. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of pydantic-settings, especially those with shared or writable sec [truncated]
CVE-2026-48782 is a medium-severity vulnerability in Pydantic AI, a Python agent framework for building applications and workflows with Generative AI. The issue affects versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2. An attacker can bypass the cloud-metadata blocklist by encoding metadata IP in an IPv6 transition form, exposing cloud IAM short-term credentials. This occurs when an application using [truncated]
CVE-2026-25580 is a high-severity Server-Side Request Forgery (SSRF) vulnerability in Pydantic AI, a Python agent framework. The vulnerability allows attackers to make HTTP requests to internal network resources by including malicious URLs in message history from untrusted sources. This could potentially lead to access to internal services or cloud credentials. The vulnerability affects applications that [truncated]