๐Ÿ›ก๏ธ NAIL Institute โ€” AVE Database

โ† Back to Database

Schema Poisoning Attack

๐ŸŸ  HIGH structural proven AVE-2025-0044

ยท aka: Pydantic Exploitation, Validation Bypass

Summary

Five distinct attack patterns exploit structured output validation (Pydantic, JSON Schema). Attackers craft inputs that pass schema validation while containing malicious payloads in unexpected fields.

Blast Radius

Validated data contains hidden malicious content. Downstream systems trust schema-validated input.

Prerequisites

Agent using structured output with schema validation (Pydantic, JSON Schema, etc.).

Environment

  • Frameworks: LangGraph
  • Models tested: [Available in NAIL SDK]
  • Multi-agent: No
  • Tools required: Yes
  • Memory required: No