Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4x9p-g9wm-8q7f | Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` |
Thu, 08 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.6 and 2.44.0, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can still export sensitive agent content through exception.message and exception.stacktrace events, error status descriptions, and model_request_parameters containing instructions or the prompted_output_template. The exposed data is available to readers of the configured telemetry backend and can include tool feedback, provider error bodies, runtime instructions, and structured-output templates even though message attributes are redacted. This issue does not grant new access to agent data, and deployments that do not use include_content=False are not affected by the setting bypass. This issue is fixed in versions 1.107.6 and 2.44.0. | |
| Title | Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` | |
| Weaknesses | CWE-212 CWE-532 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T17:25:18.280Z
Reserved: 2026-10-07T15:53:23.586Z
Link: CVE-2026-107291
No data.
Status : Received
Published: 2026-10-08T17:17:14.590
Modified: 2026-10-08T17:17:14.590
Link: CVE-2026-107291
No data.
OpenCVE Enrichment
No data.
Github GHSA