{"id":"CVE-2026-107295","title":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI","summary":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validati…","severity":"high","cvss":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L","cwe":["CWE-352","CWE-346"],"vendor":"pydantic","product":"pydantic-ai","affected":["pydantic-ai >= 1.34.0, < 1.107.4","pydantic-ai >= 2.0.0b1, < 2.28.0","pydantic-ai-slim >= 1.34.0, < 1.107.4","pydantic-ai-slim >= 2.0.0b1, < 2.28.0"],"patched":["pydantic-ai 1.107.4","pydantic-ai 2.28.0","pydantic-ai-slim 1.107.4","pydantic-ai-slim 2.28.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:35:31.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107295","references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/d2690201a1834005d382dbf5c47e0ed94ef8bf46","label":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/dd2abbdfa029c9ad138e7cc0edd2eaeaf9ed69c0","label":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7382","label":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7383","label":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.4","label":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.28.0","label":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-h4xc-3qfq-jf93","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-h4xc-3qfq-jf93"}],"tags":["nvd","cve.org","ghsa","pip"],"aliases":["GHSA-h4xc-3qfq-jf93"],"ecosystem":"pip","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-08T17:53:16.989703Z"},"ingestedAt":"2026-10-08T17:56:11.714Z","slug":"CVE-2026-107295","body":"## Overview\n\nPydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools with the privileges and credentials of the local process; client-relayed approval decisions also leave requires_approval=True tools exposed. Binding to localhost does not prevent a browser page from reaching the loopback address. This issue is fixed in versions 1.107.4 and 2.28.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107295)\n\nAffected packages:\n\n- `pydantic-ai >= 1.34.0, < 1.107.4`\n- `pydantic-ai >= 2.0.0b1, < 2.28.0`\n- `pydantic-ai-slim >= 1.34.0, < 1.107.4`\n- `pydantic-ai-slim >= 2.0.0b1, < 2.28.0`\n\nPatched in:\n\n- `pydantic-ai 1.107.4`\n- `pydantic-ai 2.28.0`\n- `pydantic-ai-slim 1.107.4`\n- `pydantic-ai-slim 2.28.0`\n\nSource: https://github.com/advisories/GHSA-h4xc-3qfq-jf93","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}