PatchSiren cyber security CVE debrief
CVE-2026-107292 pydantic CVE debrief
The Pydantic AI development web chat UI does not validate the Host header of incoming requests, allowing a website a developer visits to make requests appear same-origin to the browser. This causes the served agent to run and execute its tools with local process privileges and credentials. The consequences depend on the tools the served agent exposes and can include data disclosure and unwanted tool side effects. Current browser protections reduce but do not remove this exposure.
- Vendor
- pydantic
- Product
- pydantic-ai
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Developers serving agents through Agent.to_web() or clai web should assess exposure and verify inventory for affected versions. They should also review compensating controls for exposed systems, monitor for suspicious activity, and track exceptions. Additionally, they should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Why it matters
The vulnerability allows a website a developer visits to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and execute its tools with local process privileges and credentials.
- Data disclosure is possible if the served agent exposes sensitive data
- Unwanted tool side effects can occur if the served agent executes malicious tools
- Verification of affected versions and application of mitigations is necessary
- Monitoring for suspicious activity and tracking exceptions is required
Technical summary
The Pydantic AI development web chat UI (Agent.to_web(), clai web) does not validate the Host header of incoming requests. A website a developer visits can use DNS rebinding to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and execute its tools with the privileges and credentials of the local process. This vulnerability allows a website a developer visits to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and execute its tools with local process privileges and credentials. The consequences depend on the tools the served agent exposes and can be far
Defensive priority
Developers serving agents through Agent.to_web() or clai web should assess exposure and verify inventory for affected versions. They should apply mitigations and compensating controls, monitor for suspicious activity, and track exceptions.
Recommended defensive actions
- Assess exposure by identifying systems and applications using Pydantic AI's web chat UI
- Verify inventory for affected versions (1.34.0 to 1.107.4 and 2.0.0b1 to 2.27.1)
- Apply mitigations and compensating controls, such as validating the Host header
- Monitor for suspicious activity and track exceptions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability and its impact. The source item is a package advisory database entry from osv_dev. The CVE Program and NVD records offer additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107292 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107292
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107292 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107292
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validat
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-q2xc-rrxj-58x9.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-q2xc-rrxj-58x9
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/7437
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/7438
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/394cc1d31656620704a703a2daed752afa5135fe
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/871c7aeec5dfed2138655ccbccbf15c6d763bae7
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.5
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.