Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website visited by a developer to use DNS rebinding to reach a loopback-hosted agent as a same-origin service. The hostile page can read the served UI and submit chat requests that execute agent tools with the local process's privileges and credentials, causing data disclosure or unwanted side effects. Binding to localhost, Origin checks, and CSRF tokens do not prevent the same-origin DNS rebinding path. This issue is fixed in versions 1.107.5 and 2.30.0.
Published: 2026-10-08
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs because the Agent.to_web() method and the clai web development server do not validate the Host header. This oversight lets an attacker perform DNS rebinding from a malicious web page that a developer visits, allowing the page to target the loopback address of the local development server as if it were a same‑origin request. The attacker can then read the UI served by the server and submit chat requests that cause the agent to execute tools with the privileges of the local process. This enables unauthorized code execution and can lead to data disclosure or unintended side effects within the developer’s environment.

Affected Systems

Pydantic AI, namely the pydantic-ai and pydantic-ai-slim packages, are affected from version 1.34.0 up to and including 2.30.0. The issue was fixed in release 1.107.5 for the 1.x series and in 2.30.0 for the 2.x series.

Risk and Exploitability

The vulnerability has a CVSS score of 6.4, indicating moderate severity. EPSS data is not available and the entry is not listed in CISA’s KEV catalog. The exploit requires the target to have a locally running development server that is reachable from the attacker’s network, often via a browser. Once the attacker can deliver a crafted Host header through a DNS‑rebinding attack, the server will process the request as a legitimate same‑origin call, bypassing normal origin checks, CSRF tokens, and localhost binding restrictions. In a typical developer environment this presents a significant risk of local privilege escalation and data leakage.

Generated by OpenCVE AI on October 8, 2026 at 18:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the pydantic-ai package to at least version 1.107.5 or 2.30.0, which includes the Host header validation fix.
  • If an upgrade is not immediately feasible, limit exposure of the development chat server to trusted internal networks or localhost only so that external DNS rebinding cannot reach it.
  • Configure a reverse proxy or use baked-in HTTP Host header checks to reject requests whose Host header does not match the expected value, and enforce strict Origin checks and CSRF tokens if the framework supports them.
  • Ensure that all user‑supplied headers, especially the Host header, are validated according to input validation practices that address CWE‑346 (Unvalidated Redirects) and that sensitive data is not exposed through improper handling, covering CWE‑350 (Information Exposure).

Generated by OpenCVE AI on October 8, 2026 at 18:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q2xc-rrxj-58x9 Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header
History

Thu, 08 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Pydantic
Pydantic pydantic-ai
Vendors & Products Pydantic
Pydantic pydantic-ai

Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website visited by a developer to use DNS rebinding to reach a loopback-hosted agent as a same-origin service. The hostile page can read the served UI and submit chat requests that execute agent tools with the local process's privileges and credentials, causing data disclosure or unwanted side effects. Binding to localhost, Origin checks, and CSRF tokens do not prevent the same-origin DNS rebinding path. This issue is fixed in versions 1.107.5 and 2.30.0.
Title Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header
Weaknesses CWE-346
CWE-350
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L'}


Subscriptions

Pydantic Pydantic-ai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T16:26:48.144Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107292

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T17:17:14.770

Modified: 2026-10-08T20:35:31.200

Link: CVE-2026-107292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:30:17Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-350

    Reliance on Reverse DNS Resolution for a Security-Critical Action