Remote Code Execution Vulnerability in Pydantic AI Framework by Pydantic
CVE-2026-107292
What is CVE-2026-107292?
The Pydantic AI framework versions 1.34.0 to 2.30.0 contain a vulnerability affecting the Agent.to_web() and clai web servers, which fail to validate the Host header. This flaw allows attackers to exploit DNS rebinding, potentially accessing loopback-hosted agents. As a result, malicious sites could read sensitive data and issue commands to local agents using the privileges of the running process, leading to data leaks and potentially harmful side effects. Successful exploitation necessitates the absence of robust origin checks and CSRF tokens, emphasizing the need for users to upgrade to secure versions 1.107.5 or 2.30.0 to mitigate risks.
Affected Version(s)
pydantic-ai >= 1.34.0, < 2.0.0b1 < 1.34.0, 2.0.0b1
pydantic-ai >= 2.0.0b1, < 2.30.0 < 2.0.0b1, 2.30.0
pydantic-ai-slim >= 1.34.0, < 2.0.0b1 < 1.34.0, 2.0.0b1
