AE Agent Errors
AE-7D9R8W4R

Agent framework downloads file URLs from untrusted message history without address checks, reaching internal services and cloud metadata

SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH

Pydantic AI's download_item() helper fetched ImageUrl/AudioUrl/VideoUrl/DocumentUrl content server-side without checking that the target was a public address. Applications accepting message history from users (Agent.to_web, VercelAIAdapter, AG-UI adapters, custom APIs) could be made to request loopback, private-network and cloud metadata endpoints. The fix added SSRF protection in 1.56.0; its cloud-metadata guarantee was later found incomplete for IPv6 transition forms and fixed again in 1.99.0.

Framework / agent
Pydantic AI · LLM agent serving a chat/web interface
Remediation attempts
PARTIAL SUCCESSTESTED
Recurrence
observed
Source languages
en, und-Latn
Updated
2026-09-29

Sources

Symptoms

  • The server makes HTTP requests to attacker-supplied internal URLs contained in user message history
  • Cloud metadata endpoints can be reached, exposing cloud credentials
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-7D9R8W4R. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.