Impact
Pydantic AI’s web UI endpoint at /api/chat lacks request content‑type validation, allowing a browser‑compatible cross‑origin request to reach a locally bound chat server. When a developer visits a malicious site, the browser can send such a request to the loopback address, causing the served agent to invoke tools with the privileges and credentials of the running process. This also exposes tools requiring approval because client‑relayed approval decisions are not validated, permitting the execution of potentially dangerous operations. The vulnerability effectively grants remote code execution on the local machine for an attacker with only a malicious web page in the victim’s browser.
Affected Systems
The issue affects the pydantic‑ai and pydantic‑ai‑slim products from version 1.34.0 up to but not including 1.107.4, and earlier 2.x releases up to but not including 2.28.0. Any installation of these packages within those version ranges is vulnerable. The problem was addressed in releases 1.107.4 and 2.28.0, so upgrading to those or newer versions removes the flaw.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, while the EPSS information is unavailable. The attack can be triggered remotely through a web browser and does not require direct access to the host. A vulnerability flag is not listed in CISA’s KEV catalog, but the ease of exploitation and the local privilege escalation make this a critical concern for developers running the framework on local machines.
OpenCVE Enrichment
Github GHSA