AI and data stack advisories

Severe, 6 weeks2048Projects319

2048 severe, 6 weeks · 319 projects

pydantic-aiGHSA-q2xc-rrxj-58x9

pydantic-ai: cross-site request forgery

pydantic-ai

CVE-2026-107292 · Published Oct 8, 2026

Medium6.4
Fix: upgrade to 1.107.5 or later (2 fixed versions below)
GitHub advisory

Summary

The Pydantic AI development web chat UI (Agent.to_web(), clai web) does not validate the Host header of incoming requests. A website a developer visits can use DNS rebinding to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and to execute its tools with the privileges and credentials of the local process.

Details

Once a name the attacker controls resolves to the loopback address, the browser treats the request as same-origin, so neither an Origin check nor a CSRF token constrains it , a same-origin page can read the served UI and any token in it.

Binding the web UI to localhost , the default , does not prevent this.

Impact

Applications and developers serving an agent through Agent.to_web() or clai web. The consequences depend on the tools the served agent exposes, and can include data disclosure as well as unwanted tool side effects.

Current browser protections reduce but do not remove this exposure: Chromium's Local Network Access gates loopback subresource requests, but does not cover top-level navigations, and Safari does not implement it.

Mitigation

Upgrade to pydantic-ai/pydantic-ai-slim >= 2.30.0, or >= 1.107.5 on the v1 maintenance line.

The fix validates the Host header and rejects anything other than localhost, a loopback/LAN IP...

Affected versions

PackageAffectedFixed in
pydantic-ai
PyPI
>= 1.34.0, < 1.107.51.107.5
>= 2.0.0b1, < 2.30.02.30.0
Details and references

### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) does not validate the `Host` header of incoming requests. A website a developer visits can use DNS rebinding to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and to execute its tools with the privileges and credentials of the local process. ### Details Once a name the attacker controls resolves to the loopback address, the browser treats the request as same-origin, so neither an `Origin` check nor a CSRF token constrains it , a same-origin page can read the served UI and any token in it. Binding the web UI to localhost , the default , does not prevent this. ### Impact Applications and developers serving an agent through `Agent.to_web()` or `clai web`. The consequences depend on the tools the served agent exposes, and can include data disclosure as well as unwanted tool side effects. Current browser protections reduce but do not remove this exposure: Chromium's Local Network Access gates loopback subresource requests, but does not cover top-level navigations, and Safari does not implement it. ### Mitigation Upgrade to `pydantic-ai`/`pydantic-ai-slim` >= 2.30.0, or >= 1.107.5 on the v1 maintenance line. The fix validates the `Host` header and rejects anything other than localhost, a loopback/LAN IP address, or an explicitly allowed host, responding `421 Misdirected Request` otherwise. If you serve the web chat UI under a real hostname , behind a reverse proxy, tunnel, or similar , name it explicitly: ```python app = agent.to_web(allowed_hosts=['ui.example.com']) ```

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-346, CWE-350
Also known as
CVE-2026-107292

More pydantic-ai advisories

All pydantic-ai