{"data":{"id":"4c397576-c968-4822-9b6b-30cd8805733d","title":"GHSA-4x9p-g9wm-8q7f: Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`","summary":"Pydantic AI's OpenTelemetry instrumentation exports content that `include_content=False` was meant to exclude. Exception events on tool, agent run, model request, embedding, image generation and realtime session spans carry full messages and stack traces, the ERROR status description repeats the exception message, and `model_request_parameters` serializes the agent's instructions and prompted-output template. The exposure affects only whoever can read exported telemetry, which matters when traces go to a broader or less trusted backend.","solution":"Upgrade to a patched version. With `include_content=False`, exception events now record only the exception type, error statuses carry no description, and `model_request_parameters` is exported without its instruction content or output template. If you cannot upgrade, scrub the `exception.message` and `exception.stacktrace` event attributes, the error status description, and the instruction parts and `prompted_output_template` within","labels":["security","privacy"],"sourceUrl":"https://github.com/advisories/GHSA-4x9p-g9wm-8q7f","publishedAt":"2026-10-08T16:48:16.000Z","cveId":"CVE-2026-107291","cweIds":null,"cvssScore":null,"cvssSeverity":"low","severity":"low","attackType":["pii_leakage"],"issueType":"vulnerability","affectedPackages":["pydantic-ai-slim@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai-slim@>= 0.3.4, < 1.107.6 (fixed: 1.107.6)","pydantic-ai@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai@>= 0.3.4, < 1.107.6 (fixed: 1.107.6)"],"affectedPackageNames":["pydantic-ai-slim","pydantic-ai"],"affectedVendors":[],"affectedVendorsRaw":["Pydantic AI","OpenTelemetry"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00392,"epssCheckedAt":"2026-10-10T03:00:40.857Z","kevDateAdded":null,"advisoryAliases":["GHSA-4x9p-g9wm-8q7f"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T16:48:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}