CVE-2026-107288Low· 3.7▾ SunlitPydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107289Medium· 6.8Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
CVE-2026-107290Medium· 6.5Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
CVE-2026-107291Low· 2.3Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
CVE-2026-25580High· 8.6Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
CVE-2026-107295High· 7.6Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
CVE-2026-107294Medium· 6.5Pydantic AI is a Python agent framework for building applications and workflows with Generative AI