PT-2026-108046 · Pydantic · Pydantic-Ai+1

CVE-2026-107291

·

Publicado

2026-10-08

·

Atualizado

2026-10-08

CVSS v4.0

2.3

Baixa

VetorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.6 and 2.44.0, OpenTelemetry instrumentation configured with InstrumentationSettings(include content=False) can still export sensitive agent content through exception.message and exception.stacktrace events, error status descriptions, and model request parameters containing instructions or the prompted output template. The exposed data is available to readers of the configured telemetry backend and can include tool feedback, provider error bodies, runtime instructions, and structured-output templates even though message attributes are redacted. This issue does not grant new access to agent data, and deployments that do not use include content=False are not affected by the setting bypass. This issue is fixed in versions 1.107.6 and 2.44.0.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-107291

Produtos afetados

Pydantic-Ai
Pydantic-Ai-Slim