Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4x9p-g9wm-8q7f | Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` |
Thu, 08 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pydantic
Pydantic pydantic-ai |
|
| Vendors & Products |
Pydantic
Pydantic pydantic-ai |
Thu, 08 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.6 and 2.44.0, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can still export sensitive agent content through exception.message and exception.stacktrace events, error status descriptions, and model_request_parameters containing instructions or the prompted_output_template. The exposed data is available to readers of the configured telemetry backend and can include tool feedback, provider error bodies, runtime instructions, and structured-output templates even though message attributes are redacted. This issue does not grant new access to agent data, and deployments that do not use include_content=False are not affected by the setting bypass. This issue is fixed in versions 1.107.6 and 2.44.0. | |
| Title | Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` | |
| Weaknesses | CWE-212 CWE-532 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T17:25:18.280Z
Reserved: 2026-10-07T15:53:23.586Z
Link: CVE-2026-107291
Updated: 2026-10-08T17:25:13.936Z
Status : Awaiting Analysis
Published: 2026-10-08T17:17:14.590
Modified: 2026-10-08T20:35:31.200
Link: CVE-2026-107291
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:45:14Z
Github GHSA