Insertion of Sensitive Information into Log File Affecting pydantic-ai package, versions [0.3.4,1.107.6)[2.0.0b1,2.44.0)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.39% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PYDANTICAI-20583783
  • published8 Oct 2026
  • disclosed8 Oct 2026
  • creditBrianWillows

Introduced: 8 Oct 2026

NewCVE-2026-107291  (opens in a new tab)
CWE-212  (opens in a new tab)
CWE-532  (opens in a new tab)

How to fix?

Upgrade pydantic-ai to version 1.107.6, 2.44.0 or higher.

Overview

pydantic-ai is an AI Agent Framework, the Pydantic way

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the OpenTelemetry instrumentation layer, specifically in record_exception and related span-recording helpers, when the include_content setting is disabled. Exception events recorded on model request spans and realtime spans include the full exception message and stack trace, which can contain content the setting is intended to withhold - such as tool retry payloads, model request/response echoes, validation error arguments, and user-supplied data. An authenticated attacker with access to the exported trace data can read sensitive content that should have been suppressed.

CVSS Base Scores

version 4.0
version 3.1