Executive brief
Pydantic-settings is a library used by Python applications to manage configuration and sensitive secrets. A vulnerability in how it handles nested secret directories allows an attacker with local access to trick the application into reading files from outside the intended secrets folder by using symbolic links. This could lead to the exposure of sensitive system files or a bypass of security limits designed to prevent the loading of excessively large files.
Technical details
A path traversal and link following vulnerability exists in the NestedSecretsSettingsSource component of pydantic-settings. When 'secrets_nested_subdir=True' is configured, the library uses inconsistent directory traversal implementations: the size validation pass ignores symlinked directories, while the loading pass follows them. An attacker with the ability to create symbolic links within the secrets directory can cause the application to load arbitrary local files into its settings and bypass the 'secrets_dir_max_size' resource protection. This issue is caused by the use of 'glob.iglob' with 'recursive=True' which follows symlinks by default. The vulnerability is fixed in version 2.14.2 by implementing an explicit directory walk that validates resolved paths remain within the intended root.
Affected products
- pydantic pydantic-settings >= 2.12.0, < 2.14.2
Timeline
- 2026-06-19: advisory: GitHub security advisory published
- 2026-07-06: disclosed: CVE published to NVD
- 2026-07-06: patched: Fix released in version 2.14.2