2.3

CVE-2026-107293

Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.4 and 2.27.1, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can export retry prompts outside tool calls in gen_ai.input.messages and pydantic_ai.all_messages. Agents using NativeOutput, PromptedOutput, or output validators on text output can therefore disclose validation feedback, including invalid model values quoted by that feedback, to readers of the telemetry backend. Tool-call retries and deployments that do not use include_content=False are not affected by this specific path. This issue is fixed in versions 1.107.4 and 2.27.1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpydantic
≫
Produkt pydantic-ai
Version >= 0.3.4, < 1.107.4
Status affected
Version >= 2.0.0b1, < 2.27.1
Status affected
Herstellerpydantic
≫
Produkt pydantic-ai-slim
Version >= 0.3.4, < 1.107.4
Status affected
Version >= 2.0.0b1, < 2.27.1
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.25
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 2.3 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-3gh4-cghq-f8v4
https://github.com/pydantic/pydantic-ai/pull/7357
https://github.com/pydantic/pydantic-ai/commit/fe9dbed7b7ccf7e7128b5786886e4441f6f5594f
https://github.com/pydantic/pydantic-ai/releases/tag/v2.27.1