What happened
Two related medium/high-severity flaws in Pydantic AI's local web-development chat surface: Agent.to_web()/clai endpoints lack request Content-Type validation, so a malicious page can drive the served agent into executing tools with the local user's privileges (CVE-2026-107295, CVSS 7.6), and the same server does not validate the Host header, enabling DNS-rebinding attacks against the loopback agent (CVE-2026-107292). Both affect the developer-facing agent toolkit widely used to prototype agent apps.
Why it matters
Pydantic AI is one of the most popular Python agent frameworks; its built-in browser chat UI is designed for local development and is running precisely while the developer is most likely browsing the web for docs/Stack Overflow — an ideal watering-hole target. A successful attack executes the developer's agent tools (shell, file access, API calls) with the developer's own credentials — a browser-to-agent RCE that defeats the loopback-only assumption.
Attack vector
A website the developer visits submits a browser-compatible request (with no Content-Type validation, and via DNS rebinding to bypass loopback/Host checks) to the localhost chat server. The served agent then runs and executes its tools with the privileges and credentials of the local process; client-relayed approval decisions also leave requires_approval=True tools exposed. Binding to localhost does not stop a browser page reaching the loopback address.
Affected systems
pydantic-ai 1.34.0–1.107.4 and 2.28.0 (content-type issue; fixed 1.107.4/2.28.0); Host-header/DNS-rebinding issue 1.34.0–2.30.0 (CVE-2026-107292, fixed in 2.30.0)
Mitigation
Upgrade pydantic-ai to 1.107.4/2.28.0 (content-type) and to a version incorporating commit 394cc1d (Host-header). Use the web chat server only on trusted networks; do not keep it running while browsing untrusted sites. References: pydantic/pydantic-ai commits d2690201 and 394cc1d.