CVE-2026-107292
Received Received - Intake

Pydantic AI Agent.to_web() DNS Rebinding Vulnerability

Vulnerability report for CVE-2026-107292, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website visited by a developer to use DNS rebinding to reach a loopback-hosted agent as a same-origin service. The hostile page can read the served UI and submit chat requests that execute agent tools with the local process's privileges and credentials, causing data disclosure or unwanted side effects. Binding to localhost, Origin checks, and CSRF tokens do not prevent the same-origin DNS rebinding path. This issue is fixed in versions 1.107.5 and 2.30.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 1.34.0, < 2.0.0b1
pydantic pydantic-ai >= 2.0.0b1, < 2.30.0
pydantic pydantic-ai-slim >= 1.34.0, < 2.0.0b1
pydantic pydantic-ai-slim >= 2.0.0b1, < 2.30.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.
CWE-350 The product performs reverse DNS resolution on an IP address to obtain the hostname and make a security decision, but it does not properly ensure that the IP address is truly associated with the hostname.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pydantic AI versions 1.34.0 to 2.30.0 have a vulnerability in Agent.to_web() and the clai web development chat server where the Host header is not validated. This allows a malicious website visited by a developer to use DNS rebinding to access a locally hosted agent as if it were a same-origin service. The hostile page can then read the UI and submit chat requests that execute agent tools with the local process's privileges, leading to potential data disclosure or unwanted actions.

Detection Guidance

To detect this vulnerability, check if your Pydantic AI version is between 1.34.0 and 2.30.0. Run: pip show pydantic-ai to verify the installed version. If using the Agent.to_web() feature or clai web development chat server, inspect network traffic for unexpected Host header values or DNS rebinding attempts targeting localhost.

Impact Analysis

If you use Pydantic AI in versions 1.34.0 to 2.30.0, a malicious website could exploit this vulnerability to interact with your locally hosted agent. This could result in unauthorized data access, execution of agent tools with your system's permissions, or other malicious actions performed through the agent interface.

Compliance Impact

This vulnerability could lead to data breaches or unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Unauthorized tool execution could also result in improper data processing or disclosure, potentially leading to legal and regulatory penalties.

Mitigation Strategies

Upgrade Pydantic AI to version 1.107.5 or 2.30.0 or later immediately. Avoid using Agent.to_web() or the clai web development chat server until patched. If usage is unavoidable, restrict network access to localhost via firewall rules and monitor for suspicious DNS rebinding activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107292. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart