PT-2026-6789 · Unknown · Pydantic-Ai

·

CVE-2026-25640

·

Published

2026-02-06

·

Updated

2026-07-13

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pydantic AI versions 1.34.0 through 1.50.9
Description Pydantic AI contains a path traversal issue in its web UI. A crafted URL can be used by an attacker to serve arbitrary JavaScript within the application's context. This allows execution of attacker-controlled code in the victim's browser, potentially leading to theft of chat history and session cookies. The issue arises because the CDN URL is constructed using a non-validated version query parameter from the request URL, enabling path traversal sequences. This vulnerability affects applications utilizing Agent.to web or clai web to serve a chat interface, which may be running locally or on a remote server.
Recommendations Upgrade to version 1.51.0 or later to remove the user-controllable version parameter and prevent the vulnerability.

Exploit

Fix

XSS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25640
GHSA-WJP5-868J-WQV7
PYSEC-2026-2979
PYSEC-2026-2983

Affected Products

Pydantic-Ai