Impact
The vulnerability causes sensitive agent content to be exported through OpenTelemetry exception events even when include_content=False. Exception events can reveal tool feedback, provider error bodies, runtime instructions, and structured-output templates, leading to unintended disclosure of protected data.
Affected Systems
Affected vendors include pydantic:pydantic-ai and pydantic:pydantic-ai-slim. All releases from 0.3.4 up to and including 1.107.6 and 2.44.0 are impacted. The issue is fixed in versions 1.107.6 and 2.44.0; older and other versions remain vulnerable.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity risk. No EPSS or KEV listing suggests low exploitation probability. Exploitation requires access to the telemetry backend to read exception logs; no code execution is involved. Deployments that avoid the include_content=False setting are not affected.
OpenCVE Enrichment
Github GHSA