PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107292 pydantic CVE debrief

The Pydantic AI development web chat UI does not validate the Host header of incoming requests, allowing a website a developer visits to make requests appear same-origin to the browser. This causes the served agent to run and execute its tools with local process privileges and credentials. The consequences depend on the tools the served agent exposes and can include data disclosure and unwanted tool side effects. Current browser protections reduce but do not remove this exposure.

Vendor
pydantic
Product
pydantic-ai
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Developers serving agents through Agent.to_web() or clai web should assess exposure and verify inventory for affected versions. They should also review compensating controls for exposed systems, monitor for suspicious activity, and track exceptions. Additionally, they should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Why it matters

The vulnerability allows a website a developer visits to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and execute its tools with local process privileges and credentials.

  • Data disclosure is possible if the served agent exposes sensitive data
  • Unwanted tool side effects can occur if the served agent executes malicious tools
  • Verification of affected versions and application of mitigations is necessary
  • Monitoring for suspicious activity and tracking exceptions is required

Technical summary

The Pydantic AI development web chat UI (Agent.to_web(), clai web) does not validate the Host header of incoming requests. A website a developer visits can use DNS rebinding to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and execute its tools with the privileges and credentials of the local process. This vulnerability allows a website a developer visits to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and execute its tools with local process privileges and credentials. The consequences depend on the tools the served agent exposes and can be far

Defensive priority

Developers serving agents through Agent.to_web() or clai web should assess exposure and verify inventory for affected versions. They should apply mitigations and compensating controls, monitor for suspicious activity, and track exceptions.

Recommended defensive actions

  • Assess exposure by identifying systems and applications using Pydantic AI's web chat UI
  • Verify inventory for affected versions (1.34.0 to 1.107.4 and 2.0.0b1 to 2.27.1)
  • Apply mitigations and compensating controls, such as validating the Host header
  • Monitor for suspicious activity and track exceptions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability and its impact. The source item is a package advisory database entry from osv_dev. The CVE Program and NVD records offer additional context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107292 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107292

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107292 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107292

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validat

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-q2xc-rrxj-58x9.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-q2xc-rrxj-58x9

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/7437

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/7438

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/commit/394cc1d31656620704a703a2daed752afa5135fe

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/commit/871c7aeec5dfed2138655ccbccbf15c6d763bae7

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.5

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.