Impact
The vulnerability in Pydantic AI's web_fetch_tool allows a malicious or trainer‑influenced prompt to be crafted with an alternate IDNA spelling, non‑ASCII separator, or case variation that normalises to a blocked hostname. When the local web_fetch_tool compares the configured blocked_domains list it performs the match before either string is fully normalised, enabling the request to proceed to the unintended host. This can result in the application fetching data from any host that matches after normalization, creating potential data leakage or side‑channel exposure.
Affected Systems
This issue affects the Pydantic AI Python agent framework (pydantic:pydantic-ai and pydantic:pydantic-ai-slim) in releases from 1.77.0 through 1.107.5 and in 2.44.0 prior to the 2.44.0 patch. Versions 1.107.6 and 2.44.0 contain the fix. Any deployment that employs the local web_fetch_tool or its fallback is subject to this flaw.
Risk and Exploitability
The CVSS score of 3.7 reflects a low‑severity flaw that requires an attacker‑influenced AI model to supply a crafted hostname, so it is not a high‑profile remote code execution risk. EPSS is currently unavailable, and the vulnerability has not been listed in the CISA KEV catalog, suggesting limited exploitation activity to date. Nevertheless, since the flaw can be triggered by model prompts, operators should be aware that an attacker who can influence model behaviour may cause the application to make unexpected outbound requests, potentially exposing private data or violating network policies. The path of exploitation involves supplying a specially encoded domain in the model prompt that resolves to a blocked host after normalisation, bypassing the blocked_domains filter.
OpenCVE Enrichment