PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107295 pydantic CVE debrief

CVE-2026-107295: Pydantic AI Web chat UI vulnerability allows server-side tool execution. The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) is vulnerable to a request injection attack. A website visited by a developer can submit requests to the chat UI running on the developer's machine, causing the served agent to run and execute its tools with local privileges. This issue is mitigated in patched versions which require `Content-Type: application/json` for chat endpoint requests. Developers serving Pydantic AI agents via `Agent.to_web()` or `clai web` should verify exposure, assess tool risks, and upgrade to patched versions.

Vendor
pydantic
Product
pydantic-ai
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Developers and applications serving Pydantic AI agents via `Agent.to_web()` or `clai web` should assess exposure and take mitigation actions. This includes verifying if Pydantic AI agents are being served, evaluating the tools exposed by served agents, and upgrading to patched versions. Additionally, security teams and operators should review the vulnerability and its potential impacts on their systems and take necessary actions to prevent exploitation.

Why it matters

CVE-2026-107295 allows websites visited by developers to trigger Pydantic AI agent runs and tool execution with local privileges, potentially leading to data disclosure or unwanted side effects. Developers serving agents via `Agent.to_web()` or `clai web` should verify exposure, assess tool risks, and upgrade to patched versions.

  • Data disclosure is possible if agents expose sensitive data.
  • Unwanted tool side effects may occur depending on exposed tools.
  • Verification of agent configurations and tool approval decisions is necessary.
  • Upgrade to patched versions is recommended to prevent exploitation.

Technical summary

The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) is vulnerable to a request injection attack. A website visited by a developer can submit requests to the chat UI running on the developer's machine, causing the served agent to run and execute its tools with local privileges. This issue is mitigated in patched versions which require `Content-Type: application/json` for chat endpoint requests.

Defensive priority

Developers serving Pydantic AI agents via `Agent.to_web()` or `clai web` should verify exposure, assess tool risks, and upgrade to patched versions.

Recommended defensive actions

  • Verify if Pydantic AI agents are being served via `Agent.to_web()` or `clai web` and assess exposure.
  • Evaluate the tools exposed by served agents and potential data disclosure or unwanted side effects.
  • Upgrade to patched versions (e.g., pydantic-ai 1.107.4 or 2.28.0) which require `Content-Type: application/json` for chat endpoint requests.
  • Review and update scripts and non-browser clients to ensure they send the required `Content-Type` header.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The Pydantic AI development web chat UI did not check request content types, allowing websites visited by developers to trigger agent runs and tool execution with local privileges. Evidence is based on the supplied source corpus and CVE record. The vulnerability allows websites visited by developers to trigger Pydantic AI agent runs and tool execution with local privileges, potentially leading to data disclosure or unwanted side effects. Developers serving agents via `Agent.to_web()` or `clai web` should verify exposure, assess tool

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107295 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107295

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107295 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107295

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can t

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-h4xc-3qfq-jf93.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-h4xc-3qfq-jf93

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/7382

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/7383

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/commit/d2690201a1834005d382dbf5c47e0ed94ef8bf46

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/commit/dd2abbdfa029c9ad138e7cc0edd2eaeaf9ed69c0

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.4

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.