AE-7D9R8W4R
Agent framework downloads file URLs from untrusted message history without address checks, reaching internal services and cloud metadata
SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH
Pydantic AI's download_item() helper fetched ImageUrl/AudioUrl/VideoUrl/DocumentUrl content server-side without checking that the target was a public address. Applications accepting message history from users (Agent.to_web, VercelAIAdapter, AG-UI adapters, custom APIs) could be made to request loopback, private-network and cloud metadata endpoints. The fix added SSRF protection in 1.56.0; its cloud-metadata guarantee was later found incomplete for IPv6 transition forms and fixed again in 1.99.0.
- Framework / agent
- Pydantic AI · LLM agent serving a chat/web interface
- Remediation attempts
- PARTIAL SUCCESSTESTED
- Recurrence
- observed
- Source languages
- en, und-Latn
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling — https://github.com/pydantic/pydantic-ai, retrieved 2026-09-29
- GITHUB COMMIT Disallow downloading `FileUrl`s pointing at the local network by default (#4227) — github.com/pydantic/pydantic-ai, retrieved 2026-09-29
- SECURITY ADVISORY Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) — https://github.com/pydantic/pydantic-ai, retrieved 2026-09-29
Symptoms
- The server makes HTTP requests to attacker-supplied internal URLs contained in user message history
- Cloud metadata endpoints can be reached, exposing cloud credentials
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-7D9R8W4R. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.