Junglewise Threat Intelligence

CVE-2026-65975: Pydantic AI incorrect authorization in UI adapter message sanitization

CVE-2026-65975 · Severity: medium · CVSS 6.5 · Published 2026-07-29

Technologies: Pydantic AI Slim, PydanticAI. Vendors: Pydantic.

Executive brief

Pydantic AI is a framework used to build applications that interact with Generative AI models. A flaw in how the framework cleans up message history allows remote users to bypass certain security checks and force the system to run specific tools with their own input. While this cannot trigger tools that require manual approval, it can bypass automated guardrails that developers have placed on the AI's decision-making process, potentially leading to unauthorized actions or data access depending on the available tools.

Technical details

A vulnerability exists in the `sanitize_messages` function used by Pydantic AI's UI adapters (AG-UI and Vercel AI). The function calculates the index for stripping 'dangling' (unresolved) tool calls before sanitization occurs. If a trailing message is subsequently dropped during sanitization (such as a system message), a preceding assistant message containing a client-injected tool call can become the new tail of the history and bypass the safety check. This allows a remote attacker to execute non-approval-gated tools with schema-valid but attacker-supplied arguments. This exploit bypasses `before_model_request` and `after_model_request` hooks because the forged call skips the model interaction turn entirely. The issue is fixed in versions 1.107.1 and 2.5.0.

Affected products

  • pydantic pydantic-ai >= 1.88.0, < 1.107.1; >= 2.0.0b1, < 2.5.0
  • pydantic pydantic-ai-slim >= 1.88.0, < 1.107.1; >= 2.0.0b1, < 2.5.0

Timeline

  • 2026-07-11: advisory: GitHub Security Advisory published
  • 2026-07-29: disclosed: NVD publication date

References