<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:18:48 +0000</lastBuildDate>
    <item>
      <title>BREW-oterm-CVE-2026-54249 — Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's c…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-oterm-cve-2026-54249</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: oterm&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application&amp;#39;s model-provider or cloud-storage account. The server forwards the reference to the model provider, which fetches it using the server&amp;#39;s own credentials, allowing the client to read files it should not have access to.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;UI adapters reconstruct file parts from client-submitted message history and forward them to the model provider. File **URL** parts are validated against a scheme allowlist before being forwarded, but `UploadedFile` references — which point to a file by provider file ID or cloud-storage URI (e.g. `s3://…`, `gs://…`) — were forwarded without validation.&lt;/p&gt;
&lt;p&gt;Because the provider resolves an `UploadedFile` using the server-side identity (IAM role, service account, or provider API key) rather than the client&amp;#39;s, a client that crafts message history containing an attacker-chosen `UploadedFile` can cause the server to read objects belonging to its own account or to other tenants, given a referenceable identifier.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Applications that pass untrusted client-submitted message history to an agent through a UI adapter (such as the Vercel AI adapter). Exploitation requires the attacker to reference a valid file identifier; depending on how the application names objects, such identifiers are not always unguessable.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Upgrade to `1.106.0` (1.x) or `2.0.0b6` (the 2.x beta line), which validate `UploadedFile` referenc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: oterm&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application&amp;#39;s model-provider or cloud-storage account. The server forwards the reference to the model provider, which fetches it using the server&amp;#39;s own credentials, allowing the client to read files it should not have access to.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;UI adapters reconstruct file parts from client-submitted message history and forward them to the model provider. File **URL** parts are validated against a scheme allowlist before being forwarded, but `UploadedFile` references — which point to a file by provider file ID or cloud-storage URI (e.g. `s3://…`, `gs://…`) — were forwarded without validation.&lt;/p&gt;
&lt;p&gt;Because the provider resolves an `UploadedFile` using the server-side identity (IAM role, service account, or provider API key) rather than the client&amp;#39;s, a client that crafts message history containing an attacker-chosen `UploadedFile` can cause the server to read objects belonging to its own account or to other tenants, given a referenceable identifier.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Applications that pass untrusted client-submitted message history to an agent through a UI adapter (such as the Vercel AI adapter). Exploitation requires the attacker to reference a valid file identifier; depending on how the application names objects, such identifiers are not always unguessable.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Upgrade to `1.106.0` (1.x) or `2.0.0b6` (the 2.x beta line), which validate `UploadedFile` referenc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-oterm-cve-2026-54249</guid>
    </item>
    <item>
      <title>CVE-2026-54249 — VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via pr…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-54249</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pydantic-ai, pydantic-ai-slim&lt;/p&gt;
&lt;p&gt;Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application&amp;#39;s model-provider or cloud-storage account. While file URL parts are validated against a scheme allowlist, UploadedFile references — which point to a file by provider file ID or cloud-storage URI (e.g. s3://…, gs://…) — were forwarded without validation. Because the provider resolves an UploadedFile using the server-side identity (IAM role, service account, or provider API key) rather than the client&amp;#39;s, an attacker can craft message history to make the server read objects from its own account or other tenants, given a referenceable identifier. Exploitation requires a valid file identifier, which is not always unguessable depending on how the application names objects. This issue has been fixed in versions 1.106.0 and 2.0.0b6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pydantic-ai, pydantic-ai-slim&lt;/p&gt;
&lt;p&gt;Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application&amp;#39;s model-provider or cloud-storage account. While file URL parts are validated against a scheme allowlist, UploadedFile references — which point to a file by provider file ID or cloud-storage URI (e.g. s3://…, gs://…) — were forwarded without validation. Because the provider resolves an UploadedFile using the server-side identity (IAM role, service account, or provider API key) rather than the client&amp;#39;s, an attacker can craft message history to make the server read objects from its own account or other tenants, given a referenceable identifier. Exploitation requires a valid file identifier, which is not always unguessable depending on how the application names objects. This issue has been fixed in versions 1.106.0 and 2.0.0b6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-54249</guid>
    </item>
    <item>
      <title>GHSA-h7p7-w5gc-xj3w — Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's c…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h7p7-w5gc-xj3w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pydantic-ai-slim, PyPI: pydantic-ai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application&amp;#39;s model-provider or cloud-storage account. The server forwards the reference to the model provider, which fetches it using the server&amp;#39;s own credentials, allowing the client to read files it should not have access to.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;UI adapters reconstruct file parts from client-submitted message history and forward them to the model provider. File **URL** parts are validated against a scheme allowlist before being forwarded, but `UploadedFile` references — which point to a file by provider file ID or cloud-storage URI (e.g. `s3://…`, `gs://…`) — were forwarded without validation.&lt;/p&gt;
&lt;p&gt;Because the provider resolves an `UploadedFile` using the server-side identity (IAM role, service account, or provider API key) rather than the client&amp;#39;s, a client that crafts message history containing an attacker-chosen `UploadedFile` can cause the server to read objects belonging to its own account or to other tenants, given a referenceable identifier.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Applications that pass untrusted client-submitted message history to an agent through a UI adapter (such as the Vercel AI adapter). Exploitation requires the attacker to reference a valid file identifier; depending on how the application names objects, such identifiers are not always unguessable.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Upgrade to `1.106.0` (1.x) or `2.0.0b6` (the 2.x beta line), which validate `UploadedFile` referenc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pydantic-ai-slim, PyPI: pydantic-ai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application&amp;#39;s model-provider or cloud-storage account. The server forwards the reference to the model provider, which fetches it using the server&amp;#39;s own credentials, allowing the client to read files it should not have access to.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;UI adapters reconstruct file parts from client-submitted message history and forward them to the model provider. File **URL** parts are validated against a scheme allowlist before being forwarded, but `UploadedFile` references — which point to a file by provider file ID or cloud-storage URI (e.g. `s3://…`, `gs://…`) — were forwarded without validation.&lt;/p&gt;
&lt;p&gt;Because the provider resolves an `UploadedFile` using the server-side identity (IAM role, service account, or provider API key) rather than the client&amp;#39;s, a client that crafts message history containing an attacker-chosen `UploadedFile` can cause the server to read objects belonging to its own account or to other tenants, given a referenceable identifier.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Applications that pass untrusted client-submitted message history to an agent through a UI adapter (such as the Vercel AI adapter). Exploitation requires the attacker to reference a valid file identifier; depending on how the application names objects, such identifiers are not always unguessable.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Upgrade to `1.106.0` (1.x) or `2.0.0b6` (the 2.x beta line), which validate `UploadedFile` referenc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h7p7-w5gc-xj3w</guid>
    </item>
  </channel>
</rss>
