2.3

CVE-2026-107291

Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.6 and 2.44.0, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can still export sensitive agent content through exception.message and exception.stacktrace events, error status descriptions, and model_request_parameters containing instructions or the prompted_output_template. The exposed data is available to readers of the configured telemetry backend and can include tool feedback, provider error bodies, runtime instructions, and structured-output templates even though message attributes are redacted. This issue does not grant new access to agent data, and deployments that do not use include_content=False are not affected by the setting bypass. This issue is fixed in versions 1.107.6 and 2.44.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpydantic
≫
Produkt pydantic-ai
Version >= 0.3.4, < 1.107.6
Status affected
Version >= 2.0.0b1, < 2.44.0
Status affected
Herstellerpydantic
≫
Produkt pydantic-ai-slim
Version >= 0.3.4, < 1.107.6
Status affected
Version >= 2.0.0b1, < 2.44.0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.313
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 2.3 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6
https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0
https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-4x9p-g9wm-8q7f
https://github.com/pydantic/pydantic-ai/pull/8403
https://github.com/pydantic/pydantic-ai/pull/8404
https://github.com/pydantic/pydantic-ai/pull/8408
https://github.com/pydantic/pydantic-ai/pull/8428
https://github.com/pydantic/pydantic-ai/pull/8429
https://github.com/pydantic/pydantic-ai/commit/4e013c51a50659aba2adf7853bfb22bb77f6a518
https://github.com/pydantic/pydantic-ai/commit/6b14c74cb281f899a2ae4fae5327111e33f60771
https://github.com/pydantic/pydantic-ai/commit/7ee27e38ab2e525ca60ff1a25d16413ff989fd79
https://github.com/pydantic/pydantic-ai/commit/963dec5f70d6f558997fc259356c0090cc5ea487
https://github.com/pydantic/pydantic-ai/commit/de4e61515327bd80a19cd8552001c30933e6acc3