PT-2026-108053 · Pydantic · Pydantic-Ai+1

CVE-2026-107293

·

Publicado

2026-10-08

·

Atualizado

2026-10-08

CVSS v4.0

2.3

Baixa

VetorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.4 and 2.27.1, OpenTelemetry instrumentation configured with InstrumentationSettings(include content=False) can export retry prompts outside tool calls in gen ai.input.messages and pydantic ai.all messages. Agents using NativeOutput, PromptedOutput, or output validators on text output can therefore disclose validation feedback, including invalid model values quoted by that feedback, to readers of the telemetry backend. Tool-call retries and deployments that do not use include content=False are not affected by this specific path. This issue is fixed in versions 1.107.4 and 2.27.1.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-107293

Produtos afetados

Pydantic-Ai
Pydantic-Ai-Slim