Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.4 and 2.27.1, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can export retry prompts outside tool calls in gen_ai.input.messages and pydantic_ai.all_messages. Agents using NativeOutput, PromptedOutput, or output validators on text output can therefore disclose validation feedback, including invalid model values quoted by that feedback, to readers of the telemetry backend. Tool-call retries and deployments that do not use include_content=False are not affected by this specific path. This issue is fixed in versions 1.107.4 and 2.27.1.
Published: 2026-10-08
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure via Telemetry
Action: Patch Update
AI Analysis

Impact

This vulnerability originates in the Pydantic AI framework when OpenTelemetry instrumentation is configured with InstrumentationSettings(include_content=False). The setting mistakenly allows retry prompt content to be exported outside of tool calls in the telemetry fields gen_ai.input.messages and pydantic_ai.all_messages. As a consequence, agents using NativeOutput, PromptedOutput, or text output validators can unintentionally disclose validation feedback—including invalid model values and other sensitive prompt data—to anyone who has access to The exposed information represents a confidentiality breach that could reveal private prompt content that was intended to remain hidden.

Affected Systems

The vulnerability impacts the pydantic:pydantic-ai and pydantic:pydantic-ai-slim packages. All releases before v1.107.4 for pydantic-ai and before v2.27.1 for pydantic-ai-slim are affected. The issue is resolved in versions v1.107.4 and v2.27.1 onward.

Risk and Exploitability

The CVSS score is 2.3, indicating low severity. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely involve an attacker with read access to the telemetry backend or the ability to intercept telemetry data in transit; there is no direct remote code execution vector. The primary risk is accidental disclosure of internal prompt contents within systems’ monitoring or log collections, which can be significant in environments where telemetry is exposed to external parties.

Generated by OpenCVE AI on October 8, 2026 at 18:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Pydantic AI package to v1.107.4 or v2.27.1 (or later) to apply the official fix.
  • If updating immediately is not possible, disable OpenTelemetry instrumentation or configure it to avoid exporting retry prompts; ensure include_content=True only if that behavior is required.
  • Audit existing telemetry logs for exposed prompt content, purge or sanitize any sensitive data, and restrict access to the telemetry backend to trusted personnel.

Generated by OpenCVE AI on October 8, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3gh4-cghq-f8v4 Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`
History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.4 and 2.27.1, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can export retry prompts outside tool calls in gen_ai.input.messages and pydantic_ai.all_messages. Agents using NativeOutput, PromptedOutput, or output validators on text output can therefore disclose validation feedback, including invalid model values quoted by that feedback, to readers of the telemetry backend. Tool-call retries and deployments that do not use include_content=False are not affected by this specific path. This issue is fixed in versions 1.107.4 and 2.27.1.
Title Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`
Weaknesses CWE-212
CWE-532
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:14:30.659Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107293

cve-icon Vulnrichment

Updated: 2026-10-08T17:14:25.899Z

cve-icon NVD

Status : Received

Published: 2026-10-08T17:17:14.933

Modified: 2026-10-08T18:17:17.200

Link: CVE-2026-107293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses
  • CWE-212

    Improper Removal of Sensitive Information Before Storage or Transfer

  • CWE-532

    Insertion of Sensitive Information into Log File