CVE-2026-25640·Python vulnerability
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an attacker to serve arbitrary JavaScript in the context of the application by crafting a malicious URL. In affected versions, the CDN URL is constructed using a version query parameter from the request URL. This parameter is not validated, allowing path traversal sequences that cause the server to fetch and serve attacker-controlled HTML/JavaScript from an arbitrary source on the same CDN, instead of the legitimate chat UI package. If a victim clicks the link or visits it via an iframe, attacker-controlled code executes in their browser, enabling theft of chat history and other client-side data. This vulnerability only affects applications that use Agent.to_web to serve a chat interface and clai web to serve a chat interface from the CLI. These are typically run locally (on localhost), but may also be deployed on a remote server. This vulnerability is fixed in 1.51.0.
- Severity
- high
- Software
- Python
- Fixed in
- 1.51.0
- Published
- 2026-02-06
Affected versions
From: 1.34.0
Until: 1.51.0
Fixed in: 1.51.0
How to fix this CVE
Update Pydantic AI to version 1.51.0 or later to patch the path traversal vulnerability in the web UI component. This vulnerability allows attackers to inject malicious JavaScript through a crafted URL parameter when the chat interface is exposed via Agent.to_web() or the CLI. Immediately apply this update if you are running Pydantic AI versions 1.34.0 through 1.50.x, particularly if your application serves a web-based chat interface.
sudo dnf update python3-pydantic-aiDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
GET requests to web UI endpoint with version parameter containing path traversal sequences (e.g., 'version=../../../malicious') or unusual CDN domain references in the referer or Host headerWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement URL parameter validation to reject any 'version' query parameters containing path traversal characters (../, .., %2e%2e). Whitelist only numeric version identifiers matching the pattern '^[0-9]+\.[0-9]+\.[0-9]+$' to block exploitation attempts.How to check if you are affected
- Check installed Pydantic AI version: python3 -c "import pydantic_ai; print(pydantic_ai.__version__)"
- Verify if Agent.to_web() or CLI chat interface is exposed: grep -r "to_web\|clai web" /path/to/application/code
- Review web server logs for suspicious CDN URL requests containing path traversal sequences (../) in the version query parameter
- Confirm remediation by re-running the version check and confirming output is 1.51.0 or later
FAQ
What is CVE-2026-25640?
CVE-2026-25640 is a path traversal vulnerability in Pydantic AI's web UI component that enables attackers to serve malicious JavaScript by manipulating the CDN version parameter in URLs. When users click a crafted link or load it in an iframe, the attacker's code executes in their browser, potentially stealing chat history and session data.
Is CVE-2026-25640 being actively exploited?
No, this vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and there are no publicly available exploits. However, the relatively low complexity of exploitation means proactive patching is strongly recommended.
What versions of Pydantic AI are affected by CVE-2026-25640?
Versions 1.34.0 through 1.50.x are affected. Version 1.51.0 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-25640?
Run 'python3 -c "import pydantic_ai; print(pydantic_ai.__version__)"' and verify the output is 1.51.0 or later. Also confirm whether Agent.to_web() or 'clai web' are in use in your codebase.
Does Defensia detect CVE-2026-25640?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Pydantic AI is installed on a monitored server, CVE-2026-25640 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/pydantic/pydantic-ai/releases/tag/v1.51.0
- https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-wjp5-868j-wqv7
- https://access.redhat.com/security/cve/CVE-2026-25640
- https://bugzilla.redhat.com/show_bug.cgi?id=2437753
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25640.json
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-25640. Free for 1 server.
Get started free