GHSA-4x9p-g9wm-8q7f: Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`
- Identifiers
- CVE-2026-107291GHSA-4x9p-g9wm-8q7f
- Published
- Record updated
Summary
Pydantic AI's OpenTelemetry instrumentation exports content that `include_content=False` was meant to exclude. Exception events on tool, agent run, model request, embedding, image generation and realtime session spans carry full messages and stack traces, the ERROR status description repeats the exception message, and `model_request_parameters` serializes the agent's instructions and prompted-output template. The exposure affects only whoever can read exported telemetry, which matters when traces go to a broader or less trusted backend.
Mitigation
Upgrade to a patched version. With `include_content=False`, exception events now record only the exception type, error statuses carry no description, and `model_request_parameters` is exported without its instruction content or output template. If you cannot upgrade, scrub the `exception.message` and `exception.stacktrace` event attributes, the error status description, and the instruction parts and `prompted_output_template` within
Related items
- LowGHSA-3gh4-cghq-f8v4: Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`Similar attack · GitHub Advisory Database
- LowSeptember 2026 Cyber Threat Landscape: Global Attacks Jump 48% as Phishing and GenAI Data Exposure RiseSimilar attack · Check Point Research
- InfoIn Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI ChatsSimilar attack · SecurityWeek
- MediumOpenAI's AI agents accidentally uploaded user-provided images to third-party sitesSimilar attack · BleepingComputer
- HighCVE-2026-89032: BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that…Similar attack · NVD/CVE Database