<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pydantic-Ai - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/pydantic-ai/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:26:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/pydantic-ai/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CSRF Vulnerability in Pydantic AI Web UI Enables Unauthorized Agent Execution</title><link>https://feed.craftedsignal.io/briefs/2026-10-pydantic-ai-csrf/</link><pubDate>Thu, 08 Oct 2026 19:26:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-pydantic-ai-csrf/</guid><description>A CSRF vulnerability (CVE-2026-107295) in Pydantic AI web interfaces allows malicious websites to trigger unauthorized agent runs and tool execution on a developer's local machine.</description><content:encoded><![CDATA[<p>Pydantic AI (pydantic-ai and pydantic-ai-slim) contains a Cross-Site Request Forgery (CSRF) vulnerability, tracked as CVE-2026-107295. The flaw exists in the development web UI provided by <code>Agent.to_web()</code> and the <code>clai web</code> command. Due to insufficient validation of request headers, the local chat endpoint fails to verify the <code>Content-Type</code> of incoming requests. This allows an attacker to host a malicious website that, when visited by a developer with a running Pydantic AI instance, submits unauthorized requests to the local chat server.</p>
<p>Because the service typically binds to localhost, attackers leverage the browser context to reach the loopback interface. This exploit bypasses security controls, including tool execution approval, as the backend incorrectly trusts the request origin. Successful exploitation leads to arbitrary agent execution and local tool invocation with the privileges of the underlying developer process, potentially resulting in data exfiltration or system modification.</p>
<h2 id="impact">Impact</h2>
<p>This vulnerability affects developers and organizations using Pydantic AI for local testing and development. If exploited, an attacker can silently execute code or perform actions via the agent's defined tools on the victim's local machine. This is particularly critical when the agent is configured with tools that possess system-level access, file-write capabilities, or access to sensitive credentials.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to Pydantic AI version 1.107.4 or 2.28.0 immediately to implement the required <code>Content-Type: application/json</code> validation.</li>
<li>If upgrading is not immediately possible, terminate the Pydantic AI web UI process when browsing untrusted content or when the tool is not in active use.</li>
<li>Avoid serving agents with side-effecting or high-privilege tools through the development web UI while the instance is accessible via a web browser.</li>
<li>Audit logs for unexpected POST requests to local development endpoints if using diagnostic web servers.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>csrf</category><category>pydantic-ai</category><category>cve-2026-107295</category><category>denial-of-service</category><category>vulnerability</category></item></channel></rss>