GHSA-3gh4-cghq-f8v4: Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`
- Identifiers
- CVE-2026-107293GHSA-3gh4-cghq-f8v4
- Published
- Record updated
Summary
Pydantic AI's OpenTelemetry instrumentation records retry prompts that lack an associated tool call in full, even when `InstrumentationSettings(include_content=False)` is set. This affects structured output modes such as `NativeOutput` and `PromptedOutput`, and output validators on text output. Because validation feedback can quote invalid values from the model's response, withheld content can reach the telemetry backend, though it grants no new access to the agent or its data.
Mitigation
Upgrade to a patched version; retry prompt content now honors `include_content=False` like all other message content. If unpatched, scrub or drop the message attributes (`gen_ai.input.messages`, `gen_ai.output.messages`, `pydantic_ai.all_messages`) in your telemetry pipeline (for example with an OpenTelemetry Collector processor), or use tool-based structured output modes, whose retry feedback honors `include_content=False`.
Related items
- LowGHSA-4x9p-g9wm-8q7f: Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`Similar attack · GitHub Advisory Database
- LowSeptember 2026 Cyber Threat Landscape: Global Attacks Jump 48% as Phishing and GenAI Data Exposure RiseSimilar attack · Check Point Research
- InfoIn Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI ChatsSimilar attack · SecurityWeek
- MediumOpenAI's AI agents accidentally uploaded user-provided images to third-party sitesSimilar attack · BleepingComputer
- HighCVE-2026-89032: BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that…Similar attack · NVD/CVE Database