© 2025-2026 PySpect
First version without a known vulnerability: 0.0.0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Fixed in: 1.106.0, 2.0.0b6
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
Fixed in: 1.102.0, 2.0.0b3
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
Fixed in: 1.99.0
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
Fixed in: 1.51.0
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
Fixed in: 1.56.0