CVE-2026-107289
Beschrijving NL
Pydantic AI is een Python-agentraamwerk voor het bouwen van applicaties en workflows met Generatieve AI. Van 1.56.0 tot 1.107.6 en 2.44.0 kunnen toepassingen die door aanvallers beïnvloede URL's via FileUrl via force_download='allow-local' of web_fetch_tool met allow_local_urls=True gebruiken, de blokkeerlijst voor cloud-metagegevens omzeilen door een IPv6-zone-ID toe te voegen aan een IPv6-metagegevensadres. IPv6Adresgelijkheid en hashing omvatten de zone-id, dus de bloklijstvergelijking mislukt, ook al negeert de netwerkstack de zone op een niet-link-lokale bestemming en bereikt de metadataservice, waardoor mogelijk cloud IAM-inloggegevens worden blootgelegd. De opt-in-instellingen zijn standaard uitgeschakeld en het probleem vereist een IPv6-compatibele omgeving. Dit probleem is opgelost in versie 1.107.6 en 2.44.0.
Origineel (Engels) tonen
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address. IPv6Address equality and hashing include the zone identifier, so the blocklist comparison fails even though the network stack ignores the zone on a non-link-local destination and reaches the metadata service, potentially exposing cloud IAM credentials. The opt-in settings are disabled by default, and the issue requires an IPv6-enabled environment. This issue is fixed in versions 1.107.6 and 2.44.0.