Missing Request Content-Type Validation in Pydantic AI Framework
CVE-2026-107295

7.6HIGH

Key Information:

Vendor

Pydantic

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107295?

Pydantic AI, a Python agent framework for Generative AI applications, suffers from a flaw where the Agent.to_web() and chat endpoint lack proper request content-type validation. As a result, a malicious website can issue browser-compatible requests to a locally hosted chat server, allowing execution of tools with the local process's privileges and credentials. Additionally, approval-required tools may be exposed due to client-relayed decisions. Binding to localhost does not guard against this issue, underscoring the need for prompt updates to versions 1.107.4 and 2.28.0 which rectify this vulnerability.

Affected Version(s)

pydantic-ai >= 1.34.0, < 1.107.4 < 1.34.0, 1.107.4

pydantic-ai >= 2.0.0b1, < 2.28.0 < 2.0.0b1, 2.28.0

pydantic-ai-slim >= 1.34.0, < 1.107.4 < 1.34.0, 1.107.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.