Server-side Request Forgery (SSRF) Affecting pydantic-ai-slim package, versions [0.0.26, 1.56.0)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.58% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-PYDANTICAISLIM-15248301
  • published8 Feb 2026
  • disclosed6 Feb 2026
  • creditdoredry, Yuval Elbar

Introduced: 6 Feb 2026

CVE-2026-25580  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade pydantic-ai-slim to version 1.56.0 or higher.

Overview

pydantic-ai-slim is an Agent Framework / shim to use Pydantic with LLMs, slim package

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the download_item function. An attacker can access internal network resources, retrieve sensitive cloud metadata, or enumerate internal hosts by submitting URLs through message history.

Note: This is only exploitable if the application accepts message history or file URLs from external users.

Workaround

This vulnerability can be mitigated by filtering out URLs that target private or internal addresses using a history processor to validate and remove such URLs before processing.

References

CVSS Base Scores

version 4.0
version 3.1