THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h7p7-w5gc-xj3w (medium) — Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

[GHSA] GHSA-h7p7-w5gc-xj3w (medium) — Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

medgithub_advisoriesPublished 2026-08-13

GHSA-h7p7-w5gc-xj3w Severity: medium CVE: CVE-2026-54249

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

### Summary

A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application's model-provider or cloud-storage account. The server forwards the reference to

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h7p7-w5gc-xj3w