Description
The magic-byte checks in detect_media_type_from_base64 (agent_framework/_types.py) are too loose in some places and too strict in others:
data.startswith(b"BM") returns image/bmp for any payload starting with "BM" (e.g. the text BMW is a car).
data.startswith(b"<?xml") returns image/svg+xml for any XML document (RSS, XHTML, plain XML).
- Only
\xff\xfb / \xff\xf3 are treated as MP3 frame sync. MPEG-2/2.5 Layer III (\xff\xf2, \xff\xe3, ...) returns None.
base64.b64decode is called without validate=True, so non-alphabet characters are silently discarded instead of producing the documented ValueError.
Suggested fix: for BMP, also validate the DIB header size at offset 14 (12/40/56/108/124). For SVG, require an <svg element near the start. For MP3, use the frame-sync mask b0 == 0xFF and (b1 & 0xE0) == 0xE0 plus a layer check. Decode with validate=True.
Related but separate: #8786 / PR #8787 (OpenAI clients and audio/mpeg).
Code Sample
from agent_framework import detect_media_type_from_base64 as d
d(data_bytes=b"BMW is a car") # 'image/bmp'
d(data_bytes=b"<?xml version='1.0'?><rss/>") # 'image/svg+xml'
d(data_bytes=b"\xff\xf2\x90\x00" + b"\0" * 20) # None (MPEG-2 Layer III frame)
d(data_str="iVBO!!!!Rw0KGgowMDAwMDAwMA==") # 'image/png' (invalid chars ignored)
Error Messages / Stack Traces
Package Versions
agent-framework-core 1.19.0 (main @ 853c456)
Python Version
Python 3.11
Additional Context
Found during a code review of main @ 853c456 (2026-09-30); the repro above was run against that commit.
Description
The magic-byte checks in
detect_media_type_from_base64(agent_framework/_types.py) are too loose in some places and too strict in others:data.startswith(b"BM")returnsimage/bmpfor any payload starting with "BM" (e.g. the textBMW is a car).data.startswith(b"<?xml")returnsimage/svg+xmlfor any XML document (RSS, XHTML, plain XML).\xff\xfb/\xff\xf3are treated as MP3 frame sync. MPEG-2/2.5 Layer III (\xff\xf2,\xff\xe3, ...) returnsNone.base64.b64decodeis called withoutvalidate=True, so non-alphabet characters are silently discarded instead of producing the documentedValueError.Suggested fix: for BMP, also validate the DIB header size at offset 14 (12/40/56/108/124). For SVG, require an
<svgelement near the start. For MP3, use the frame-sync maskb0 == 0xFF and (b1 & 0xE0) == 0xE0plus a layer check. Decode withvalidate=True.Related but separate: #8786 / PR #8787 (OpenAI clients and
audio/mpeg).Code Sample
Error Messages / Stack Traces
Package Versions
agent-framework-core 1.19.0 (main @ 853c456)
Python Version
Python 3.11
Additional Context
Found during a code review of
main@853c456(2026-09-30); the repro above was run against that commit.