Missing Request Content-Type Validation in Pydantic AI Framework
CVE-2026-107295
What is CVE-2026-107295?
Pydantic AI, a Python agent framework for Generative AI applications, suffers from a flaw where the Agent.to_web() and chat endpoint lack proper request content-type validation. As a result, a malicious website can issue browser-compatible requests to a locally hosted chat server, allowing execution of tools with the local process's privileges and credentials. Additionally, approval-required tools may be exposed due to client-relayed decisions. Binding to localhost does not guard against this issue, underscoring the need for prompt updates to versions 1.107.4 and 2.28.0 which rectify this vulnerability.
Affected Version(s)
pydantic-ai >= 1.34.0, < 1.107.4 < 1.34.0, 1.107.4
pydantic-ai >= 2.0.0b1, < 2.28.0 < 2.0.0b1, 2.28.0
pydantic-ai-slim >= 1.34.0, < 1.107.4 < 1.34.0, 1.107.4
