Pydantic AI shipped v2.52.0 on 2026-09-30 (pydantic-ai==2.52.0): ctx.workspace unifies local/sandbox file+command APIs with E2B, Fly.io Sprites, Modal, SSH, and Bubblewrap backends; harness moves in-repo to 0.52.0; first pydantic-clai2 release (uvx pydantic-clai2). Also patches local web_fetch nested-HTML resource exhaustion (GHSA-v36g-jcw9-x7cw, CVSS 6.5) and adds Claude Sonnet 5.5 plus GPT-6.1 Sol support.

Key Takeaways

  • ✓Release v2.52.0; 533 commits ahead of v2.51.0
  • ✓Security: local web_fetch nested-HTML DoS patched (GHSA-v36g-jcw9-x7cw, CVSS 6.5); v1 patch 1.107.7; provider-native fetch unaffected
  • ✓Workspaces via ctx.workspace (#6492) with E2B/Sprites/Modal/SSH/Bubblewrap backends; harness in-repo at 0.52.0; CLAI2 first release
  • ✓Models: Claude Sonnet 5.5 (#8974), GPT-6.1 Sol (#9305); Anthropic default max_tokens 16384 on Sonnet 4.5+ (#9025)
  • ✓Upgrade: pip install -U 'pydantic-ai==2.52.0'; uvx pydantic-clai2; docs: Workspace + Harness
🧭

Finished reading? Explore benchmark rankings & pricing

Real-world SWE-bench scores & $20/mo vs API cost break-even calculator

🔬

In-Depth Technical Analysis

Background Agent harnesses needed one workspace API across local and sandboxes, while local web_fetch HTML→Markdown conversion could DoS on nested attacker HTML. v2.52.0 ships both the workspace model and the security fix. ### What shipped v2.52.0: ctx.workspace (#6492) with E2B/Sprites/Modal/SSH/Bubblewrap; harness in-repo at 0.52.0; first pydantic-clai2 (uvx pydantic-clai2); Claude Sonnet 5.5 + GPT-6.1 Sol; Anthropic default max_tokens 16384 on Sonnet 4.5+. 533 commits ahead of v2.51.0. ### Benchmarks / security No SWE-bench in the notes. Advisory GHSA-v36g-jcw9-x7cw CVSS 6.5; patched in 2.52.0 / 1.107.7. Provider-native fetch unaffected. ### Get started pip install -U 'pydantic-ai==2.52.0'; route tools through ctx.workspace; uvx pydantic-clai2. Docs: Workspace, Harness.