What is CVE-2026-65975?
This vulnerability exists in the Pydantic AI framework where the UI adapters (AG-UI and Vercel AI) fail to properly sanitize user inputs via the `sanitize_m` function. Versions from 1.88.0 up to but not including 1.107.1, and from 2.0.0b1 up to but not including 2.5.0 are affected, potentially allowing crafted prompts to cause unexpected behavior in Generative AI workflows. Immediate update to versions 1.107.1 or 2.5.0 is recommended.
Azərbaycanca: Bu boşluq Pydantic AI çərçivəsində UI adapterlərinin (AG-UI, Vercel AI) `sanitize_m` funksiyası vasitəsilə istifadəçi daxiletmələrini düzgün təmizləməməsi ilə bağlıdır. 1.88.0-dən 1.107.1-ə qədər və 2.0.0b1-dən 2.5.0-a qədər olan versiyalar təsirə məruz qalır, belə ki, xüsusi hazırlanmış sorğular Generativ AI iş axınlarında gözlənilməz davranışa səbəb ola bilər. Təsirlənmiş sistemləri dərhal 1.107.1 və ya 2.5.0 versiyalarına yeniləmək tövsiyə olunur.
FAQ2
Which versions of Pydantic AI are affected by CVE-2026-65975?
Versions from 1.88.0 up to but not including 1.107.1, and from 2.0.0b1 up to but not including 2.5.0 are affected.
How can CVE-2026-65975 be mitigated?
It is recommended to immediately update affected systems to versions 1.107.1 or 2.5.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.