GHSA-q2xc-rrxj-58x9: CSRF
Summary
The Pydantic AI development web chat UI (Agent.toweb(), clai web) does not validate the Host header of incoming requests. A website a developer visits can use DNS rebinding to make requests to a chat UI running on that developer's machine appear same-origin to the browser, causing the served agent to run and to execute its tools with the privileges and credentials of the local process.
Details
Once a name the attacker controls resolves to the loopback address, the browser treats the request as same-origin, so neither an Origin check nor a CSRF token constrains it — a same-origin page can read the served UI and any token in it.
Binding the web UI to localhost — the default — does not prevent this.
Impact
Applications and developers serving an agent through Agent.toweb() or clai web. The consequences depend on the tools the served agent exposes, and can include data disclosure as well as unwanted tool side effects.
Current browser protections reduce but do not remove this exposure: Chromium's Local Network Access gates loopback subresource requests, but does not cover top-level navigations, and Safari does not implement it.
Mitigation
Upgrade to pydantic-ai/pydantic-ai-slim >= 2.30.0, or >= 1.107.5 on the v1 maintenance line.
The fix validates the Host header and rejects anything other than localhost, a loopback/LAN IP address, or an explicitly allowed host, responding 421 Misdirected Request otherwise. If you serve the web chat UI under a real hostname — behind a reverse proxy, tunnel, or similar — name it explicitly:
python app = agent.toweb(allowedhosts=['ui.example.com'])
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pydantic-ai-slimto a version that resolves this vulnerability.Fixed in 2.30.0 - Upgrade
Upgrade
pip/pydantic-ai-slimto a version that resolves this vulnerability.Fixed in 1.107.5 - Upgrade
Upgrade
pip/pydantic-aito a version that resolves this vulnerability.Fixed in 2.30.0 - Upgrade
Upgrade
pip/pydantic-aito a version that resolves this vulnerability.Fixed in 1.107.5 - Upgrade
Upgrade
pydantic-ai/pydantic-ai-slimto a version that resolves this vulnerability.Fixed in 2.30.0 - Configuration
When serving the UI under a real hostname, configure Agent.to_web(allowed_hosts=['ui.example.com']) with the explicitly allowed hostname.
Pydantic AI development web chat UI allowed_hosts = ui.example.com
Event History
Frequently Asked Questions
Who is exposed to this issue?
Developers or applications serving an agent through Agent.to_web() or clai web are exposed. The web UI being bound to localhost, which is the default, does not prevent the attack.
What does an attacker need to exploit it?
A developer must visit a website controlled by the attacker. The attacker can use DNS rebinding so requests to the locally running chat UI appear same-origin in the browser.
What could an attacker do through a vulnerable local chat UI?
The attacker can cause the served agent to run and execute its exposed tools using the local process's privileges and credentials. Impact depends on the available tools and can include data disclosure and unwanted tool side effects.
Do browser protections prevent exploitation?
No. Chromium's Local Network Access restricts loopback subresource requests, but not top-level navigations, and Safari does not implement this protection.