Impact
The vulnerability occurs because the Agent.to_web() method and the clai web development server do not validate the Host header. This oversight lets an attacker perform DNS rebinding from a malicious web page that a developer visits, allowing the page to target the loopback address of the local development server as if it were a same‑origin request. The attacker can then read the UI served by the server and submit chat requests that cause the agent to execute tools with the privileges of the local process. This enables unauthorized code execution and can lead to data disclosure or unintended side effects within the developer’s environment.
Affected Systems
Pydantic AI, namely the pydantic-ai and pydantic-ai-slim packages, are affected from version 1.34.0 up to and including 2.30.0. The issue was fixed in release 1.107.5 for the 1.x series and in 2.30.0 for the 2.x series.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating moderate severity. EPSS data is not available and the entry is not listed in CISA’s KEV catalog. The exploit requires the target to have a locally running development server that is reachable from the attacker’s network, often via a browser. Once the attacker can deliver a crafted Host header through a DNS‑rebinding attack, the server will process the request as a legitimate same‑origin call, bypassing normal origin checks, CSRF tokens, and localhost binding restrictions. In a typical developer environment this presents a significant risk of local privilege escalation and data leakage.
OpenCVE Enrichment
Github GHSA