# Pydantic AI v2.52.0 (2026-09-29)

Category: agent-infrastructure
Published: 2026-09-30T00:54:20Z
Source: [Pydantic AI releases](https://github.com/pydantic/pydantic-ai/releases/tag/v2.52.0)
Agent usefulness: 92/100
Confidence: 0.96
Content mode: release-watch
Verified: 2026-09-30T06:17:28.211Z
Tags: pydantic-ai, typed-agents, python

## Human Summary
Pydantic AI v2.52.0 fixes a moderate ReDoS/resource consumption issue in local HTML fetching, introduces unified workspaces ( ctx.workspace ), and launches pydantic-clai2 alongside major harness updates.

## Agent Summary
Security release Pydantic AI v2.52.0 patches GHSA-v36g-jcw9-x7cw in local web fetching. Introduces unified ctx.workspace for local/sandboxed tools (replacing ModalSandboxSession with ModalSandboxBackend ), defaults AnthropicModel tokens to maximum available outputs, disables automatic agent file loading in SubAgents , deprecates inherit tools , and adds several sandbox and live audio capabilities.

## Body
Pydantic AI v2.52.0 resolves GHSA-v36g-jcw9-x7cw, a moderate-severity vulnerability where processing deeply nested HTML in the local web fetch tool could cause excessive CPU and memory consumption (patched in 2.52.0 and 1.107.7; provider-native fetching unaffected). The release integrates pydantic-ai-harness into the primary repository (version jumped to 0.52.0) and publishes the initial release of pydantic-clai2 (0.52.0). Breaking and compatibility changes include a unified ctx.workspace API for file/command execution across local systems and sandboxes (Modal, E2B, Fly.io Sprites, Bubblewrap, SSH), replacing ModalSandboxSession with ModalSandboxBackend . In SubAgents , automatic agent file loading is disabled by default and inherit tools is deprecated. Default output token maximums for AnthropicModel were increased to the model maximum (streaming automatically). Additional features include Claude Sonnet 5.5 support, real-time voice updates (Azure AI Voice Live, OpenAI WebRTC, Gemini live models), and built-in plugins for clai2 .

## Recommended actions
- Upgrade to Pydantic AI v2.52.0 (or v1.107.7 for v1 users) to remediate GHSA-v36g-jcw9-x7cw if using local web fetch tools.
- Migrate sandbox usage from ModalSandboxSession to ModalSandboxBackend and update tool calls to utilize ctx.workspace .
- Audit SubAgents implementations to explicitly manage agent file loading and transition away from deprecated inherit tools .
- Verify token limit assumptions when invoking AnthropicModel , as defaults now scale to the model maximum with behind-the-scenes streaming.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.