---
id: CVE-2026-107292
title: >-
  Pydantic AI is a Python agent framework for building applications and
  workflows with Generative AI
summary: >-
  Pydantic AI is a Python agent framework for building applications and
  workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and
  clai web development chat server does not validate the Host header, allowing a
  website v…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L'
cwe:
  - CWE-346
  - CWE-350
vendor: pydantic-ai
product: pydantic-ai
affected:
  - 'pydantic-ai >= 1.34.0, < 1.107.5'
  - 'pydantic-ai >= 2.0.0b1, < 2.30.0'
  - 'pydantic-ai-slim >= 1.34.0, < 1.107.5'
  - 'pydantic-ai-slim >= 2.0.0b1, < 2.30.0'
patched:
  - pydantic-ai 1.107.5
  - pydantic-ai 2.30.0
  - pydantic-ai-slim 1.107.5
  - pydantic-ai-slim 2.30.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:35:31.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107292'
references:
  - url: >-
      https://github.com/pydantic/pydantic-ai/commit/394cc1d31656620704a703a2daed752afa5135fe
    label: security-advisories@github.com
  - url: >-
      https://github.com/pydantic/pydantic-ai/commit/871c7aeec5dfed2138655ccbccbf15c6d763bae7
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/pull/7437'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/pull/7438'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.5'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/releases/tag/v2.30.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-q2xc-rrxj-58x9
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-q2xc-rrxj-58x9'
tags:
  - nvd
  - ghsa
  - pip
  - cve.org
aliases:
  - GHSA-q2xc-rrxj-58x9
ecosystem: pip
ingestedAt: '2026-10-08T16:52:14.785Z'
---

## Overview

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website visited by a developer to use DNS rebinding to reach a loopback-hosted agent as a same-origin service. The hostile page can read the served UI and submit chat requests that execute agent tools with the local process's privileges and credentials, causing data disclosure or unwanted side effects. Binding to localhost, Origin checks, and CSRF tokens do not prevent the same-origin DNS rebinding path. This issue is fixed in versions 1.107.5 and 2.30.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107292)

Affected packages:

- `pydantic-ai >= 1.34.0, < 1.107.5`
- `pydantic-ai >= 2.0.0b1, < 2.30.0`
- `pydantic-ai-slim >= 1.34.0, < 1.107.5`
- `pydantic-ai-slim >= 2.0.0b1, < 2.30.0`

Patched in:

- `pydantic-ai 1.107.5`
- `pydantic-ai 2.30.0`
- `pydantic-ai-slim 1.107.5`
- `pydantic-ai-slim 2.30.0`

Source: https://github.com/advisories/GHSA-q2xc-rrxj-58x9
