Impact
This vulnerability originates in the Pydantic AI framework when OpenTelemetry instrumentation is configured with InstrumentationSettings(include_content=False). The setting mistakenly allows retry prompt content to be exported outside of tool calls in the telemetry fields gen_ai.input.messages and pydantic_ai.all_messages. As a consequence, agents using NativeOutput, PromptedOutput, or text output validators can unintentionally disclose validation feedback—including invalid model values and other sensitive prompt data—to anyone who has access to The exposed information represents a confidentiality breach that could reveal private prompt content that was intended to remain hidden.
Affected Systems
The vulnerability impacts the pydantic:pydantic-ai and pydantic:pydantic-ai-slim packages. All releases before v1.107.4 for pydantic-ai and before v2.27.1 for pydantic-ai-slim are affected. The issue is resolved in versions v1.107.4 and v2.27.1 onward.
Risk and Exploitability
The CVSS score is 2.3, indicating low severity. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely involve an attacker with read access to the telemetry backend or the ability to intercept telemetry data in transit; there is no direct remote code execution vector. The primary risk is accidental disclosure of internal prompt contents within systems’ monitoring or log collections, which can be significant in environments where telemetry is exposed to external parties.
OpenCVE Enrichment
Github GHSA