{"data":{"id":"dc2acd77-32e5-472a-b1af-32fa3af8cff5","title":"GHSA-q2xc-rrxj-58x9: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header","summary":"The Pydantic AI development web chat UI, served through `Agent.to_web()` and `clai web`, does not validate the `Host` header of incoming requests. Using DNS rebinding, a website a developer visits can make the browser treat requests to the local chat UI as same-origin, so the served agent runs and its tools execute with the privileges and credentials of the local process. Binding to localhost, the default, does not prevent this, and current browser protections only partly reduce the exposure.","solution":"Upgrade `pydantic-ai`/`pydantic-ai-slim` to >= 2.30.0, or to >= 1.107.5 on the v1 maintenance line. The fix validates the `Host` header and rejects anything other than localhost, a loopback/LAN IP address, or an explicitly allowed host, responding `421 Misdirected Request`. If the web chat UI is served under a real hostname, such as behind a reverse proxy or tunnel, name it explicitly with `app = agent.to_web(allowed_hosts=['ui.example.com'])`.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-q2xc-rrxj-58x9","publishedAt":"2026-10-08T17:16:39.000Z","cveId":"CVE-2026-107292","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["pydantic-ai-slim@>= 2.0.0b1, < 2.30.0 (fixed: 2.30.0)","pydantic-ai-slim@>= 1.34.0, < 1.107.5 (fixed: 1.107.5)","pydantic-ai@>= 2.0.0b1, < 2.30.0 (fixed: 2.30.0)","pydantic-ai@>= 1.34.0, < 1.107.5 (fixed: 1.107.5)"],"affectedPackageNames":["pydantic-ai-slim","pydantic-ai"],"affectedVendors":[],"affectedVendorsRaw":["Pydantic AI","clai web","Agent.to_web()"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00132,"epssCheckedAt":"2026-10-10T02:57:56.487Z","kevDateAdded":null,"advisoryAliases":["GHSA-q2xc-rrxj-58x9"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T17:16:39.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}