CVE-2026-107295
Received Received - Intake

Server-Side Request Forgery in Pydantic AI

Vulnerability report for CVE-2026-107295, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools with the privileges and credentials of the local process; client-relayed approval decisions also leave requires_approval=True tools exposed. Binding to localhost does not prevent a browser page from reaching the loopback address. This issue is fixed in versions 1.107.4 and 2.28.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 1.34.0, < 1.107.4
pydantic pydantic-ai >= 2.0.0b1, < 2.28.0
pydantic pydantic-ai-slim >= 1.34.0, < 1.107.4
pydantic pydantic-ai-slim >= 2.0.0b1, < 2.28.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pydantic AI versions between 1.34.0 and 1.107.4 and 2.28.0 have a flaw where the Agent.to_web() function and CLI web development chat endpoint lack proper request content-type validation. This allows a malicious website visited by a developer to send a specially crafted request to a locally hosted chat server, potentially executing tools with the local process's privileges and credentials.

Detection Guidance

Check if your Pydantic AI version is between 1.34.0 and 1.107.4 or 2.28.0. Inspect network traffic for unexpected requests to localhost chat endpoints. Look for tools with requires_approval=True being triggered without proper validation.

Impact Analysis

If exploited, this vulnerability could allow an attacker to run arbitrary tools on your local machine with the same permissions as the Pydantic AI process. This could lead to unauthorized code execution, data theft, or further compromise of your system, especially if the tools have elevated privileges.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by enabling unauthorized execution of tools with local process privileges. If an attacker exploits this to run tools handling sensitive data, it may lead to data disclosure or unauthorized processing, violating GDPR principles of data protection and HIPAA requirements for safeguarding protected health information.

Mitigation Strategies

Upgrade Pydantic AI to versions 1.107.4 or 2.28.0 or later immediately. Disable Agent.to_web() if not needed. Restrict localhost access via firewall rules. Review and update tool approval policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107295. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart