GHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint
- Identifiers
- CVE-2026-107295GHSA-h4xc-3qfq-jf93
- Published
- Record updated
Summary
The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) did not check the content type of requests to its chat endpoint. A website visited by a developer could submit a request to the chat UI on that developer's machine, causing the served agent to run and execute its tools with the privileges and credentials of the local process, including tools marked `requires_approval=True`, because the endpoint trusts approval decisions relayed by the client.
Mitigation
Upgrade to a patched version. The chat endpoint now requires `Content-Type: application/json` and rejects other requests before the request body is parsed and before the agent runs. Scripts and other non-browser clients calling the endpoint directly may need to send this header. If you cannot upgrade, don't run the web UI while browsing untrusted sites, stop it when not in use, and don't serve an agent with side-effecting tools through it.
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review
- InfoMicrosoft Teams to get support for third-party deepfake detection toolsSame vendor · BleepingComputer
- InfoMicrosoft to sell $2,599 Surface Laptop Ultra containing Nvidia AI chipSame vendor · CNBC Technology