Data Exposure in Pydantic AI Framework by OpenTelemetry Instrumentation
CVE-2026-107291
What is CVE-2026-107291?
The Pydantic AI framework, designed for leveraging Generative AI applications, has a vulnerability related to OpenTelemetry instrumentation. When the configuration option 'InstrumentationSettings(include_content=False)' is used, sensitive information such as error messages, runtime instructions, and detailed model request parameters can still be exported through various events. This can potentially expose critical operational insights and execution details to unauthorized users accessing the telemetry backend. Although this setting, when properly configured, does not grant new access to agent data, systems using the aforementioned option are at risk. To mitigate this issue, users should update to versions 1.107.6 or 2.44.0 where the vulnerability has been addressed.
Affected Version(s)
pydantic-ai >= 0.3.4, < 1.107.6 < 0.3.4, 1.107.6
pydantic-ai >= 2.0.0b1, < 2.44.0 < 2.0.0b1, 2.44.0
pydantic-ai-slim >= 0.3.4, < 1.107.6 < 0.3.4, 1.107.6
