Disclosure summary
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website visited by a developer to use DNS rebinding to reach a loopback-hosted agent as a same-origin service. The hostile page can read the served UI and submit chat requests that execute agent tools with the local process's privileges and credentials, causing data disclosure or unwanted side effects. Binding to localhost, Origin checks, and CSRF tokens do not prevent the same-origin DNS rebinding path. This issue is fixed in versions 1.107.5 and 2.30.0.
Source-reported weakness categories
CWE-346, CWE-350
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107292
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-q2xc-rrxj-58x9
Open original source · Updated Oct 08, 2026
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | pydantic-ai | >= 1.34.0, < 1.107.5 | 1.107.5 |
| pip | pydantic-ai | >= 2.0.0b1, < 2.30.0 | 2.30.0 |
| pip | pydantic-ai-slim | >= 1.34.0, < 1.107.5 | 1.107.5 |
| pip | pydantic-ai-slim | >= 2.0.0b1, < 2.30.0 | 2.30.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
PUBLISHED 2026-10-08T13:17:14-04:00
MODIFIED 2026-10-08T16:35:31-04:00
INGESTED 2026-10-10T20:55:03-04:00