CVE-2026-107295: `pydantic-ai-slim` web UI `/api/chat` accepts browser-simple cross-origin requests that can trigger agent tool execution

Published Oct 8, 2026
·
Updated

Summary

The Pydantic AI development web chat UI (Agent.toweb(), clai web) did not check the content type of requests to its chat endpoint. This allowed a website visited by a developer to submit a request to a chat UI running on that developer's machine, causing the served agent to run and to execute its tools with the privileges and credentials of the local process.

Binding the web UI to localhost — the default — does not prevent this, because a page open in the developer's browser can reach the loopback address.

Impact

Applications and developers serving an agent through Agent.toweb() or clai web. The consequences depend on the tools the served agent exposes, and can include data disclosure as well as unwanted tool side effects. Tools marked requiresapproval=True were not protected either, because the endpoint trusts approval decisions relayed by the client.

Mitigation

Upgrade to a patched version. The chat endpoint now requires Content-Type: application/json and rejects other requests before the request body is parsed and before the agent runs. The bundled chat UI already sends this header; scripts and other non-browser clients that call the endpoint directly may need to be updated to send it.

If you cannot upgrade, don't run the web UI while browsing untrusted sites, stop it when you aren't using it, and don't serve an agent with side-effecting tools through it.

Credits - Thai Son Dinh from VinSOC Labs (R&D)

Other sources

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.toweb() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools with the privileges and credentials of the local process; client-relayed approval decisions also leave requiresapproval=True tools exposed. Binding to localhost does not prevent a browser page from reaching the loopback address. This issue is fixed in versions 1.107.4 and 2.28.0.

— MITRE

Affected Software

5 affected componentsFixes available
pypi/pydantic-ai-slim>=1.34.0<1.107.4, >=2.0.0<2.28.0
pip/pydantic-ai-slim>=2.0.0b1<2.28.0
2.28.0
pip/pydantic-ai-slim>=1.34.0<1.107.4
1.107.4
pip/pydantic-ai>=2.0.0b1<2.28.0
2.28.0
pip/pydantic-ai>=1.34.0<1.107.4
1.107.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pydantic-ai-slim to a version that resolves this vulnerability.

    Fixed in 2.28.0
  2. Upgrade

    Upgrade pip/pydantic-ai-slim to a version that resolves this vulnerability.

    Fixed in 1.107.4
  3. Upgrade

    Upgrade pip/pydantic-ai to a version that resolves this vulnerability.

    Fixed in 2.28.0
  4. Upgrade

    Upgrade pip/pydantic-ai to a version that resolves this vulnerability.

    Fixed in 1.107.4
  5. Upgrade

    Upgrade Pydantic AI to a version that resolves this vulnerability.

    Fixed in 1.107.4
  6. Upgrade

    Upgrade Pydantic AI to a version that resolves this vulnerability.

    Fixed in 2.28.0
  7. Configuration

    Update scripts and other non-browser clients to send Content-Type: application/json when calling the chat endpoint.

    Pydantic AI development web chat UI /api/chat Content-Type = application/json
  8. Compensating control

    If you cannot upgrade, do not run the web UI while browsing untrusted sites, stop it when it is not in use, and do not serve an agent with side-effecting tools through it.

Event History

Oct 8, 2026
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·05:16 PM
Data Sourced
via GitHub·05:16 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Developers and applications that serve an agent through Agent.to_web() or clai web are exposed. The impact depends on the tools available to the served agent and the privileges and credentials of its local process.

2

Does binding the web UI only to localhost prevent exploitation?

No. Localhost is the default binding, but a website opened in the developer's browser can still send requests to the loopback address.

3

Can tools that require approval still be triggered?

Yes. Tools marked requires_approval=True were not protected because the endpoint trusted approval decisions relayed by the client.

4

What changes after upgrading, and could it affect API clients?

The patched endpoint requires Content-Type: application/json and rejects other content types before parsing the body or running the agent. The bundled chat UI already sends this header, but scripts and other non-browser clients calling the endpoint may need to send it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203