CSRF Vulnerability in Pydantic AI Web UI Enables Unauthorized Agent Execution
A CSRF vulnerability (CVE-2026-107295) in Pydantic AI web interfaces allows malicious websites to trigger unauthorized agent runs and tool execution on a developer's local machine.
CVE search metadata
CVE search record: CVE-2026-107295. Severity: high. CVSS: 7.6. KEV: no. Product: pydantic-ai (>= 1.34.0, < 1.107.4 and >= 2.0.0b1, < 2.28.0), pydantic-ai-slim (>= 1.34.0, < 1.107.4 and >= 2.0.0b1, < 2.28.0), pydantic-ai (>= 2.10.0, < 2.53.0), pydantic-ai-slim (>= 2.10.0, < 2.53.0). Brief: CSRF Vulnerability in Pydantic AI Web UI Enables Unauthorized Agent Execution. Brief link: https://feed.craftedsignal.io/briefs/2026-10-pydantic-ai-csrf/
What's new
- 1. added coverage for pydantic-ai (>= 2.10.0, < 2.53.0) +1 products Oct 8, 19:57 via ghsa
Pydantic AI (pydantic-ai and pydantic-ai-slim) contains a Cross-Site Request Forgery (CSRF) vulnerability, tracked as CVE-2026-107295. The flaw exists in the development web UI provided by Agent.to_web() and the clai web command. Due to insufficient validation of request headers, the local chat endpoint fails to verify the Content-Type of incoming requests. This allows an attacker to host a malicious website that, when visited by a developer with a running Pydantic AI instance, submits unauthorized requests to the local chat server.
Because the service typically binds to localhost, attackers leverage the browser context to reach the loopback interface. This exploit bypasses security controls, including tool execution approval, as the backend incorrectly trusts the request origin. Successful exploitation leads to arbitrary agent execution and local tool invocation with the privileges of the underlying developer process, potentially resulting in data exfiltration or system modification.
Impact
This vulnerability affects developers and organizations using Pydantic AI for local testing and development. If exploited, an attacker can silently execute code or perform actions via the agent's defined tools on the victim's local machine. This is particularly critical when the agent is configured with tools that possess system-level access, file-write capabilities, or access to sensitive credentials.
Recommendation
- Upgrade to Pydantic AI version 1.107.4 or 2.28.0 immediately to implement the required
Content-Type: application/jsonvalidation. - If upgrading is not immediately possible, terminate the Pydantic AI web UI process when browsing untrusted content or when the tool is not in active use.
- Avoid serving agents with side-effecting or high-privilege tools through the development web UI while the instance is accessible via a web browser.
- Audit logs for unexpected POST requests to local development endpoints if using diagnostic web servers.
Immediate actions
Upgrade pydantic-ai or pydantic-ai-slim to version 1.107.4 or 2.28.0.
Mitigations
Stop the Pydantic AI web UI when browsing untrusted websites.
CVE-2026-107295