PatchSiren cyber security CVE debrief
CVE-2026-107295 pydantic CVE debrief
CVE-2026-107295: Pydantic AI Web chat UI vulnerability allows server-side tool execution. The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) is vulnerable to a request injection attack. A website visited by a developer can submit requests to the chat UI running on the developer's machine, causing the served agent to run and execute its tools with local privileges. This issue is mitigated in patched versions which require `Content-Type: application/json` for chat endpoint requests. Developers serving Pydantic AI agents via `Agent.to_web()` or `clai web` should verify exposure, assess tool risks, and upgrade to patched versions.
- Vendor
- pydantic
- Product
- pydantic-ai
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Developers and applications serving Pydantic AI agents via `Agent.to_web()` or `clai web` should assess exposure and take mitigation actions. This includes verifying if Pydantic AI agents are being served, evaluating the tools exposed by served agents, and upgrading to patched versions. Additionally, security teams and operators should review the vulnerability and its potential impacts on their systems and take necessary actions to prevent exploitation.
Why it matters
CVE-2026-107295 allows websites visited by developers to trigger Pydantic AI agent runs and tool execution with local privileges, potentially leading to data disclosure or unwanted side effects. Developers serving agents via `Agent.to_web()` or `clai web` should verify exposure, assess tool risks, and upgrade to patched versions.
- Data disclosure is possible if agents expose sensitive data.
- Unwanted tool side effects may occur depending on exposed tools.
- Verification of agent configurations and tool approval decisions is necessary.
- Upgrade to patched versions is recommended to prevent exploitation.
Technical summary
The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) is vulnerable to a request injection attack. A website visited by a developer can submit requests to the chat UI running on the developer's machine, causing the served agent to run and execute its tools with local privileges. This issue is mitigated in patched versions which require `Content-Type: application/json` for chat endpoint requests.
Defensive priority
Developers serving Pydantic AI agents via `Agent.to_web()` or `clai web` should verify exposure, assess tool risks, and upgrade to patched versions.
Recommended defensive actions
- Verify if Pydantic AI agents are being served via `Agent.to_web()` or `clai web` and assess exposure.
- Evaluate the tools exposed by served agents and potential data disclosure or unwanted side effects.
- Upgrade to patched versions (e.g., pydantic-ai 1.107.4 or 2.28.0) which require `Content-Type: application/json` for chat endpoint requests.
- Review and update scripts and non-browser clients to ensure they send the required `Content-Type` header.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The Pydantic AI development web chat UI did not check request content types, allowing websites visited by developers to trigger agent runs and tool execution with local privileges. Evidence is based on the supplied source corpus and CVE record. The vulnerability allows websites visited by developers to trigger Pydantic AI agent runs and tool execution with local privileges, potentially leading to data disclosure or unwanted side effects. Developers serving agents via `Agent.to_web()` or `clai web` should verify exposure, assess tool
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107295 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107295
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107295 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107295
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can t
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-h4xc-3qfq-jf93.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-h4xc-3qfq-jf93
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/7382
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/7383
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/d2690201a1834005d382dbf5c47e0ed94ef8bf46
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/dd2abbdfa029c9ad138e7cc0edd2eaeaf9ed69c0
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.4
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.