CVE-2026-107295 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.
Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools with the privileges and credentials of the local process; client-relayed approval decisions also leave requires_approval=True tools exposed. Binding to localhost does not prevent a browser page from reaching the loopback address. This issue is fixed in versions 1.107.4 and 2.28.0.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:LHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
High
Integrity
A
Low
Availability
Affected
- Vendor
- PyPI
- Product
- pydantic-ai
Versions
- pkg:pypi/pydantic-ai >= 1.34.0, < 1.107.4
- pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.28.0
- pkg:pypi/pydantic-ai-slim >= 1.34.0, < 1.107.4
- pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.28.0
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/pydantic/pydantic-ai/commit/d2690201a1834005d382dbf5c47e0ed94ef8bf46
- advisory[email protected]https://github.com/pydantic/pydantic-ai/commit/dd2abbdfa029c9ad138e7cc0edd2eaeaf9ed69c0
- advisory[email protected]https://github.com/pydantic/pydantic-ai/pull/7382
- advisory[email protected]https://github.com/pydantic/pydantic-ai/pull/7383
- advisory[email protected]https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.4
- advisory[email protected]https://github.com/pydantic/pydantic-ai/releases/tag/v2.28.0
- advisory[email protected]https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-h4xc-3qfq-jf93
- advisoryOSV GHSA-h4xc-3qfq-jf93https://osv.dev/vulnerability/GHSA-h4xc-3qfq-jf93
- vendorOSV packagehttps://github.com/pydantic/pydantic-ai
Related threats
same CWE or vendorCVE-2026-107831 — Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing …
CVE-2026-107831 · 4h ago
CVE-2026-78388 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery whi…
CVE-2026-78388 · 5h ago
PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-60086 · 7h ago
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433 · 7h ago
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-61435 · 7h ago
CVE-2026-107378 — CairoSVG is an SVG converter based on Cairo, a 2D graphics library.
CVE-2026-107378 · 8h ago