Agent InfrastructureAutomated release watch

Pydantic AI v2.52.0 (2026-09-29)

Pydantic AI v2.52.0 fixes a moderate ReDoS/resource consumption issue in local HTML fetching, introduces unified workspaces ( ctx.workspace ), and launches pydantic-clai2 alongside major harness updates.

Human read

Why this signal matters

Pydantic AI v2.52.0 resolves GHSA-v36g-jcw9-x7cw, a moderate-severity vulnerability where processing deeply nested HTML in the local web fetch tool could cause excessive CPU and memory consumption (patched in 2.52.0 and 1.107.7; provider-native fetching unaffected). The release integrates pydantic-ai-harness into the primary repository (version jumped to 0.52.0) and publishes the initial release of pydantic-clai2 (0.52.0). Breaking and compatibility changes include a unified ctx.workspace API for file/command execution across local systems and sandboxes (Modal, E2B, Fly.io Sprites, Bubblewrap, SSH), replacing ModalSandboxSession with ModalSandboxBackend . In SubAgents , automatic agent file loading is disabled by default and inherit tools is deprecated. Default output token maximums for AnthropicModel were increased to the model maximum (streaming automatically). Additional features include Claude Sonnet 5.5 support, real-time voice updates (Azure AI Voice Live, OpenAI WebRTC, Gemini live models), and built-in plugins for clai2 .

Agent parse

Actionable summary

Security release Pydantic AI v2.52.0 patches GHSA-v36g-jcw9-x7cw in local web fetching. Introduces unified ctx.workspace for local/sandboxed tools (replacing ModalSandboxSession with ModalSandboxBackend ), defaults AnthropicModel tokens to maximum available outputs, disables automatic agent file loading in SubAgents , deprecates inherit tools , and adds several sandbox and live audio capabilities.

Agent usefulness
92/100
Confidence
96%
Canonical data
JSON + Markdown
Next actions

What builders should check

  • Upgrade to Pydantic AI v2.52.0 (or v1.107.7 for v1 users) to remediate GHSA-v36g-jcw9-x7cw if using local web fetch tools.
  • Migrate sandbox usage from ModalSandboxSession to ModalSandboxBackend and update tool calls to utilize ctx.workspace .
  • Audit SubAgents implementations to explicitly manage agent file loading and transition away from deprecated inherit tools .
  • Verify token limit assumptions when invoking AnthropicModel , as defaults now scale to the model maximum with behind-the-scenes streaming.
Classification

Tags and routing

pydantic-aityped-agentspython
Related signals

Continue the thread