THREAT OPS › Threat News › [GHSA] GHSA-h7p7-w5gc-xj3w (medium) — Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
[GHSA] GHSA-h7p7-w5gc-xj3w (medium) — Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
GHSA-h7p7-w5gc-xj3w Severity: medium CVE: CVE-2026-54249
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
### Summary
A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application's model-provider or cloud-storage account. The server forwards the reference to
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-54249cve
Original source: https://github.com/advisories/GHSA-h7p7-w5gc-xj3w