The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade pydantic-ai to version 1.107.6, 2.44.0 or higher.
pydantic-ai is an AI Agent Framework, the Pydantic way
Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the OpenTelemetry instrumentation layer, specifically in record_exception and related span-recording helpers, when the include_content setting is disabled. Exception events recorded on model request spans and realtime spans include the full exception message and stack trace, which can contain content the setting is intended to withhold - such as tool retry payloads, model request/response echoes, validation error arguments, and user-supplied data. An authenticated attacker with access to the exported trace data can read sensitive content that should have been suppressed.