Skip to content
MediumVulnerability

GHSA-q2xc-rrxj-58x9: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header

Published
Record updated
View JSON
Affected
  • pydantic-ai-slim >= 2.0.0b1, < 2.30.0, fixed in 2.30.0
  • pydantic-ai-slim >= 1.34.0, < 1.107.5, fixed in 1.107.5
  • pydantic-ai >= 2.0.0b1, < 2.30.0, fixed in 2.30.0
  • and 1 more
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.1%

Summary

The Pydantic AI development web chat UI, served through `Agent.to_web()` and `clai web`, does not validate the `Host` header of incoming requests. Using DNS rebinding, a website a developer visits can make the browser treat requests to the local chat UI as same-origin, so the served agent runs and its tools execute with the privileges and credentials of the local process. Binding to localhost, the default, does not prevent this, and current browser protections only partly reduce the exposure.

Mitigation

Upgrade `pydantic-ai`/`pydantic-ai-slim` to >= 2.30.0, or to >= 1.107.5 on the v1 maintenance line. The fix validates the `Host` header and rejects anything other than localhost, a loopback/LAN IP address, or an explicitly allowed host, responding `421 Misdirected Request`. If the web chat UI is served under a real hostname, such as behind a reverse proxy or tunnel, name it explicitly with `app = agent.to_web(allowed_hosts=['ui.example.com'])`.