{"data":{"id":"b5fd5924-7a5d-4fb8-9f98-141acb67d91a","title":"GHSA-3gh4-cghq-f8v4: Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`","summary":"Pydantic AI's OpenTelemetry instrumentation records retry prompts that lack an associated tool call in full, even when `InstrumentationSettings(include_content=False)` is set. This affects structured output modes such as `NativeOutput` and `PromptedOutput`, and output validators on text output. Because validation feedback can quote invalid values from the model's response, withheld content can reach the telemetry backend, though it grants no new access to the agent or its data.","solution":"Upgrade to a patched version; retry prompt content now honors `include_content=False` like all other message content. If unpatched, scrub or drop the message attributes (`gen_ai.input.messages`, `gen_ai.output.messages`, `pydantic_ai.all_messages`) in your telemetry pipeline (for example with an OpenTelemetry Collector processor), or use tool-based structured output modes, whose retry feedback honors `include_content=False`.","labels":["security","privacy"],"sourceUrl":"https://github.com/advisories/GHSA-3gh4-cghq-f8v4","publishedAt":"2026-10-08T17:16:32.000Z","cveId":"CVE-2026-107293","cweIds":null,"cvssScore":null,"cvssSeverity":"low","severity":"low","attackType":["pii_leakage"],"issueType":"vulnerability","affectedPackages":["pydantic-ai-slim@>= 2.0.0b1, < 2.27.1 (fixed: 2.27.1)","pydantic-ai-slim@>= 0.3.4, < 1.107.4 (fixed: 1.107.4)","pydantic-ai@>= 2.0.0b1, < 2.27.1 (fixed: 2.27.1)","pydantic-ai@>= 0.3.4, < 1.107.4 (fixed: 1.107.4)"],"affectedPackageNames":["pydantic-ai-slim","pydantic-ai"],"affectedVendors":[],"affectedVendorsRaw":["Pydantic AI"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00336,"epssCheckedAt":"2026-10-10T02:56:35.067Z","kevDateAdded":null,"advisoryAliases":["GHSA-3gh4-cghq-f8v4"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T17:16:32.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}