{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/pydantic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pydantic:pydantic-ai:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-107295"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pydantic-ai (\u003e= 1.34.0, \u003c 1.107.4 and \u003e= 2.0.0b1, \u003c 2.28.0)","pydantic-ai-slim (\u003e= 1.34.0, \u003c 1.107.4 and \u003e= 2.0.0b1, \u003c 2.28.0)","pydantic-ai (\u003e= 2.10.0, \u003c 2.53.0)","pydantic-ai-slim (\u003e= 2.10.0, \u003c 2.53.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","csrf","pydantic-ai","cve-2026-107295","denial-of-service","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Pydantic"],"content_html":"\u003cp\u003ePydantic AI (pydantic-ai and pydantic-ai-slim) contains a Cross-Site Request Forgery (CSRF) vulnerability, tracked as CVE-2026-107295. The flaw exists in the development web UI provided by \u003ccode\u003eAgent.to_web()\u003c/code\u003e and the \u003ccode\u003eclai web\u003c/code\u003e command. Due to insufficient validation of request headers, the local chat endpoint fails to verify the \u003ccode\u003eContent-Type\u003c/code\u003e of incoming requests. This allows an attacker to host a malicious website that, when visited by a developer with a running Pydantic AI instance, submits unauthorized requests to the local chat server.\u003c/p\u003e\n\u003cp\u003eBecause the service typically binds to localhost, attackers leverage the browser context to reach the loopback interface. This exploit bypasses security controls, including tool execution approval, as the backend incorrectly trusts the request origin. Successful exploitation leads to arbitrary agent execution and local tool invocation with the privileges of the underlying developer process, potentially resulting in data exfiltration or system modification.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis vulnerability affects developers and organizations using Pydantic AI for local testing and development. If exploited, an attacker can silently execute code or perform actions via the agent's defined tools on the victim's local machine. This is particularly critical when the agent is configured with tools that possess system-level access, file-write capabilities, or access to sensitive credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Pydantic AI version 1.107.4 or 2.28.0 immediately to implement the required \u003ccode\u003eContent-Type: application/json\u003c/code\u003e validation.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, terminate the Pydantic AI web UI process when browsing untrusted content or when the tool is not in active use.\u003c/li\u003e\n\u003cli\u003eAvoid serving agents with side-effecting or high-privilege tools through the development web UI while the instance is accessible via a web browser.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected POST requests to local development endpoints if using diagnostic web servers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:57:58Z","date_published":"2026-10-08T19:26:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-pydantic-ai-csrf/","summary":"A CSRF vulnerability (CVE-2026-107295) in Pydantic AI web interfaces allows malicious websites to trigger unauthorized agent runs and tool execution on a developer's local machine.","title":"CSRF Vulnerability in Pydantic AI Web UI Enables Unauthorized Agent Execution","url":"https://feed.craftedsignal.io/briefs/2026-10-pydantic-ai-csrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Pydantic","version":"https://jsonfeed.org/version/1.1"}