{"data":{"id":"4804dac9-4e8d-40f2-809b-51aa8f8fbb91","title":"GHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint","summary":"The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) did not check the content type of requests to its chat endpoint. A website visited by a developer could submit a request to the chat UI on that developer's machine, causing the served agent to run and execute its tools with the privileges and credentials of the local process, including tools marked `requires_approval=True`, because the endpoint trusts approval decisions relayed by the client.","solution":"Upgrade to a patched version. The chat endpoint now requires `Content-Type: application/json` and rejects other requests before the request body is parsed and before the agent runs. Scripts and other non-browser clients calling the endpoint directly may need to send this header. If you cannot upgrade, don't run the web UI while browsing untrusted sites, stop it when not in use, and don't serve an agent with side-effecting tools through it.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-h4xc-3qfq-jf93","publishedAt":"2026-10-08T17:16:36.000Z","cveId":"CVE-2026-107295","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["pydantic-ai-slim@>= 2.0.0b1, < 2.28.0 (fixed: 2.28.0)","pydantic-ai-slim@>= 1.34.0, < 1.107.4 (fixed: 1.107.4)","pydantic-ai@>= 2.0.0b1, < 2.28.0 (fixed: 2.28.0)","pydantic-ai@>= 1.34.0, < 1.107.4 (fixed: 1.107.4)"],"affectedPackageNames":["pydantic-ai-slim","pydantic-ai"],"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Pydantic AI","Agent.to_web()","clai web"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.0016,"epssCheckedAt":"2026-10-10T03:00:40.857Z","kevDateAdded":null,"advisoryAliases":["GHSA-h4xc-3qfq-jf93"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T17:16:36.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}