GHSA-q2xc-rrxj-58x9: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header
- Identifiers
- CVE-2026-107292GHSA-q2xc-rrxj-58x9
- Published
- Record updated
- Affected
- pydantic-ai-slim >= 2.0.0b1, < 2.30.0, fixed in 2.30.0
- pydantic-ai-slim >= 1.34.0, < 1.107.5, fixed in 1.107.5
- pydantic-ai >= 2.0.0b1, < 2.30.0, fixed in 2.30.0
- and 1 more
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.1%
Summary
The Pydantic AI development web chat UI, served through `Agent.to_web()` and `clai web`, does not validate the `Host` header of incoming requests. Using DNS rebinding, a website a developer visits can make the browser treat requests to the local chat UI as same-origin, so the served agent runs and its tools execute with the privileges and credentials of the local process. Binding to localhost, the default, does not prevent this, and current browser protections only partly reduce the exposure.
Mitigation
Upgrade `pydantic-ai`/`pydantic-ai-slim` to >= 2.30.0, or to >= 1.107.5 on the v1 maintenance line. The fix validates the `Host` header and rejects anything other than localhost, a loopback/LAN IP address, or an explicitly allowed host, responding `421 Misdirected Request`. If the web chat UI is served under a real hostname, such as behind a reverse proxy or tunnel, name it explicitly with `app = agent.to_web(allowed_hosts=['ui.example.com'])`.
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database