Skip to main content

CVE-2026-107292: CWE-346: Origin Validation Error in pydantic pydantic-ai

0
Medium
Published: 10/08/2026 (10/08/2026, 17:16:39 UTC)
Source: CVE Database V5
Vendor/Project: pydantic
Product: pydantic-ai

Description

### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) does not validate the `Host` header of incoming requests. A website a developer visits can use DNS rebinding to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and to execute its tools with the privileges and credentials of the local process. ### Details Once a name the attacker controls resolves to the loopback address, the browser treats the request as same-origin, so neither an `Origin` check nor a CSRF token constrains it — a same-origin page can read the served UI and any token in it. Binding the web UI to localhost — the default — does not prevent this. ### Impact Applications and developers serving an agent through `Agent.to_web()` or `clai web`. The consequences depend on the tools the served agent exposes, and can include data disclosure as well as unwanted tool side effects. Current browser protections reduce but do not remove this exposure: Chromium's Local Network Access gates loopback subresource requests, but does not cover top-level navigations, and Safari does not implement it. ### Mitigation Upgrade to `pydantic-ai`/`pydantic-ai-slim` >= 2.30.0, or >= 1.107.5 on the v1 maintenance line. The fix validates the `Host` header and rejects anything other than localhost, a loopback/LAN IP address, or an explicitly allowed host, responding `421 Misdirected Request` otherwise. If you serve the web chat UI under a real hostname — behind a reverse proxy, tunnel, or similar — name it explicitly: ```python app = agent.to_web(allowed_hosts=['ui.example.com']) ```

CVSS v3.1

Score 6.4medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L

Affected software

pydantic

pydantic-ai

Affected versions
>=1.34.0 <2.0.0b1>=2.0.0b1 <2.30.0

pydantic

pydantic-ai-slim

Affected versions
>=1.34.0 <2.0.0b1>=2.0.0b1 <2.30.0
pydantic-ai
pkg:pypi/pydantic-ai
Affected versions
>=1.34.0 <2.0.0b1>=2.0.0b1 <2.30.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 16:48:38 UTC

Technical Analysis

Pydantic AI, a Python agent framework for Generative AI applications, contains an origin validation flaw (CWE-346) in its web server components (Agent.to_web() and clai chat server) from versions 1.34.0 until 2.30.0. The flaw arises because the Host header is not properly validated, allowing DNS rebinding attacks that bypass protections such as binding to localhost, Origin checks, and CSRF tokens. This enables a malicious website visited by a developer to access the loopback-hosted agent as a same-origin service, read the UI, and submit chat requests that execute agent tools with the local process's privileges and credentials. The vulnerability is addressed in versions 1.107.5 and 2.30.0.

Potential Impact

Exploitation of this vulnerability allows a remote attacker controlling a malicious website to perform DNS rebinding attacks against a developer's local pydantic-ai agent instance. This can lead to unauthorized execution of agent tools with the local process's privileges, resulting in potential data disclosure and unwanted side effects. The CVSS score of 6.4 reflects a medium severity with low confidentiality impact but high integrity impact and low availability impact.

Mitigation Recommendations

Users should upgrade to pydantic-ai versions 1.107.5 or 2.30.0 or later where this vulnerability is fixed. No other mitigations such as binding to localhost, Origin checks, or CSRF tokens are sufficient to prevent exploitation. Patch status is confirmed fixed in these versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T15:53:23.586Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac7c7552cdf04f6562a0001

Added to database: 10/08/2026, 16:39:49 UTC

Last enriched: 10/08/2026, 16:48:38 UTC

Last updated: 10/08/2026, 21:48:53 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses