CVE-2026-107292: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header

Published Oct 8, 2026
·
Updated

Summary

The Pydantic AI development web chat UI (Agent.toweb(), clai web) does not validate the Host header of incoming requests. A website a developer visits can use DNS rebinding to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and to execute its tools with the privileges and credentials of the local process.

Details

Once a name the attacker controls resolves to the loopback address, the browser treats the request as same-origin, so neither an Origin check nor a CSRF token constrains it — a same-origin page can read the served UI and any token in it.

Binding the web UI to localhost — the default — does not prevent this.

Impact

Applications and developers serving an agent through Agent.toweb() or clai web. The consequences depend on the tools the served agent exposes, and can include data disclosure as well as unwanted tool side effects.

Current browser protections reduce but do not remove this exposure: Chromium's Local Network Access gates loopback subresource requests, but does not cover top-level navigations, and Safari does not implement it.

Mitigation

Upgrade to pydantic-ai/pydantic-ai-slim >= 2.30.0, or >= 1.107.5 on the v1 maintenance line.

The fix validates the Host header and rejects anything other than localhost, a loopback/LAN IP address, or an explicitly allowed host, responding 421 Misdirected Request otherwise. If you serve the web chat UI under a real hostname — behind a reverse proxy, tunnel, or similar — name it explicitly:

python app = agent.toweb(allowedhosts=['ui.example.com'])

Other sources

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.toweb() and clai web development chat server does not validate the Host header, allowing a website visited by a developer to use DNS rebinding to reach a loopback-hosted agent as a same-origin service. The hostile page can read the served UI and submit chat requests that execute agent tools with the local process's privileges and credentials, causing data disclosure or unwanted side effects. Binding to localhost, Origin checks, and CSRF tokens do not prevent the same-origin DNS rebinding path. This issue is fixed in versions 1.107.5 and 2.30.0.

— MITRE

Affected Software

5 affected componentsFixes available
pypi/pydantic-ai>=1.34.0<1.107.5, >=2.0.0<2.30.0
pip/pydantic-ai-slim>=2.0.0b1<2.30.0
2.30.0
pip/pydantic-ai-slim>=1.34.0<1.107.5
1.107.5
pip/pydantic-ai>=2.0.0b1<2.30.0
2.30.0
pip/pydantic-ai>=1.34.0<1.107.5
1.107.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pydantic-ai-slim to a version that resolves this vulnerability.

    Fixed in 2.30.0
  2. Upgrade

    Upgrade pip/pydantic-ai-slim to a version that resolves this vulnerability.

    Fixed in 1.107.5
  3. Upgrade

    Upgrade pip/pydantic-ai to a version that resolves this vulnerability.

    Fixed in 2.30.0
  4. Upgrade

    Upgrade pip/pydantic-ai to a version that resolves this vulnerability.

    Fixed in 1.107.5
  5. Upgrade

    Upgrade pydantic-ai to a version that resolves this vulnerability.

    Fixed in 2.30.0
  6. Upgrade

    Upgrade pydantic-ai to a version that resolves this vulnerability.

    Fixed in 1.107.5
  7. Configuration

    When serving the web chat UI under a real hostname, explicitly configure allowed_hosts=['ui.example.com'].

    Agent.to_web() / clai web allowed_hosts = ui.example.com

Event History

Oct 8, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·05:16 PM
Data Sourced
via GitHub·05:16 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Developers running the development chat server through Agent.to_web() or clai web are exposed in the affected versions. The issue affects versions from 1.34.0 until the fixes in 1.107.5 and 2.30.0.

2

What must an attacker do to exploit this?

A developer must visit a hostile website. That site can use DNS rebinding to access the developer's loopback-hosted agent server as a same-origin service, read its UI, and submit chat requests.

3

Does binding the server to localhost protect against this issue?

No. Binding to localhost does not prevent the DNS-rebinding same-origin path; Origin checks and CSRF tokens also do not prevent it.

4

What is the available remediation?

Upgrade to Pydantic AI version 1.107.5 or 2.30.0, which contain the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203