What is CVE-2026-46678?
CVE-2026-46678 is a vulnerability discovered in the Pydantic AI framework. In versions 1.56.0 through 1.98.0, when the `force_download='allow-local'` option is enabled, the cloud-metadata blocklist can be bypassed via specially encoded requests. Users are urged to immediately update to the latest patched version.
Azərbaycanca: CVE-2026-46678, Pydantic AI framework-ündə aşkarlanmış boşluqdur. 1.56.0 - 1.98.0 versiyalarında `force_download='allow-local'` seçimi aktiv olduqda, xüsusi kodlanmış sorğularla cloud-metadata bloklama siyahısını keçmək mümkündür. İstifadəçilərə təcili olaraq bu versiyalardan ən son təhlükəsizlik yeniləməsinə keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of Pydantic AI are affected by CVE-2026-46678?
This vulnerability exists in Pydantic AI framework versions 1.56.0 through 1.98.0.
How can users protect against CVE-2026-46678?
Users are urged to immediately update from the affected versions to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.