pydantic-ai-slim is vulnerable to Server-Side Request Forgery (SSRF)
37
Low Risk
The local web_fetch_tool's allowed_domains/blocked_domains lists compare a hostname to their entries by exact string match, without putting either side in the form the DNS resolver actually uses. A hostname written with fullwidth or other non-ASCII label separator characters resolves to a blocked domain while the string comparison reads it as a different name, letting a model chosen URL reach a domain the list was meant to block. The fix compares both the request hostname and the list entries in the ASCII form the resolver produces before matching.
You are affected if you are using a version that falls within the vulnerable range and you rely on blocked_domains on the local web-fetch tool to restrict which hosts a model chosen URL may reach.
pydantic-ai-slim is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.77.0 - 1.107.5 and 2.0.0 - 2.43.0.
Upgrade the pydantic-ai-slim and/or the pydantic-ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.