CVE-2026-107295: Pydantic Pydantic-Ai
High severity, CVSS 7.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools with the privileges and credentials of the local process; client-relayed approval decisions also leave requires_approval=True tools exposed. Binding to localhost does not prevent a browser page from reaching the loopback address. This issue is fixed in versions 1.107.4 and 2.28.0.
Affected products
- Pydantic Pydantic-Ai: from 1.34.0, before 1.107.4 (fixed in 1.107.4); from 2.0.0b1, before 2.28.0 (fixed in 2.28.0)
- Pydantic Pydantic-Ai-Slim: from 1.34.0, before 1.107.4 (fixed in 1.107.4); from 2.0.0b1, before 2.28.0 (fixed in 2.28.0)
Published 2026-10-08. Last modified 2026-10-08.