{"schema_version":"1.9.0","id":"GHSA-3gh4-cghq-f8v4","published":"2026-10-08T17:16:32Z","modified":"2026-10-08T17:31:45.445283071Z","aliases":["CVE-2026-107293"],"summary":"Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`","details":"### Summary\n\nPydantic AI's OpenTelemetry instrumentation supports `InstrumentationSettings(include_content=False)` to exclude message content — user prompts, model completions, tool call arguments and responses — from exported telemetry, so that agents can be monitored without sending sensitive content to the observability backend.\n\nRetry prompts — the feedback messages Pydantic AI sends back to the model when its output fails validation or an output validator raises `ModelRetry` — were not covered by this setting when they were not associated with a tool call, as with structured output modes that don't use tool calls (e.g. `NativeOutput` or `PromptedOutput`) and output validators applied to text output. Their full content was recorded on model request spans even with `include_content=False`. Since validation feedback can quote invalid values from the model's response, message content that the setting was configured to withhold could reach the telemetry backend.\n\n### Details\n\nRetry prompts without an associated tool call were serialized into span message attributes (such as `gen_ai.input.messages` and `pydantic_ai.all_messages`) as regular text parts, and this path did not apply the `include_content` check that every other message part applies. Retry prompts tied to a tool call, and all other message content, were redacted correctly.\n\n### Impact\n\nThis does not grant an attacker any new access to the agent or its data: the content is only visible to whoever can read the exported telemetry. The exposure matters when traces are exported to a destination whose audience is broader or less trusted than the agent's own data — a third-party observability vendor or a shared backend — which is the scenario `include_content=False` exists for. The disclosed content is limited to retry feedback: validation error details, which can quote invalid values from the model's output, or output-validator `ModelRetry` messages.\n\n### Who Is Affected\n\nYou are affected if you enabled instrumentation with `include_content=False` and your agent can produce retry prompts outside of tool calls: it uses a structured output mode that doesn't rely on tool calls (such as `NativeOutput` or `PromptedOutput`), or output validators on text output. You are not affected if you don't set `include_content=False`, or if all of your agent's retries come from tool calls (including the default tool-based structured output mode), which were redacted correctly.\n\n### Remediation\n\nUpgrade to a patched version; retry prompt content now honors `include_content=False` like all other message content. If you rely on this setting, consider reviewing previously exported traces for retry prompt content that should not have been recorded.\n\n### Workaround for Unpatched Versions\n\nIf you cannot upgrade, scrub or drop the message attributes (`gen_ai.input.messages`, `gen_ai.output.messages`, `pydantic_ai.all_messages`) in your telemetry pipeline (for example with an OpenTelemetry Collector processor), or use tool-based structured output modes, whose retry feedback honors `include_content=False`.\n\n### Credits\n\nReported privately by the University of Sydney Security Research Team (Liyi Zhou, Ziyue Wang, Strick, Maurice, Chenchen Yu), and later independently discovered and reported publicly, with a fix, by @sean-kim05.","affected":[{"package":{"name":"pydantic-ai","ecosystem":"PyPI","purl":"pkg:pypi/pydantic-ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.3.4"},{"fixed":"1.107.4"}]}],"versions":["0.3.4","0.3.5","0.3.6","0.3.7","0.4.0","0.4.1","0.4.10","0.4.11","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.4.8","0.4.9","0.5.0","0.5.1","0.6.0","0.6.1","0.6.2","0.7.0","0.7.1","0.7.2","0.7.3","0.7.4","0.7.5","0.7.6","0.8.0","0.8.1","1.0.0","1.0.0b1","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.10.0","1.100.0","1.101.0","1.102.0","1.103.0","1.104.0","1.105.0","1.106.0","1.107.0","1.107.1","1.107.2","1.11.0","1.11.1","1.12.0","1.13.0","1.14.0","1.14.1","1.15.0","1.16.0","1.17.0","1.18.0","1.19.0","1.2.0","1.2.1","1.20.0","1.21.0","1.22.0","1.23.0","1.24.0","1.25.0","1.25.1","1.26.0","1.27.0","1.28.0","1.29.0","1.3.0","1.30.0","1.30.1","1.31.0","1.32.0","1.33.0","1.34.0","1.35.0","1.36.0","1.37.0","1.38.0","1.39.0","1.39.1","1.4.0","1.40.0","1.41.0","1.42.0","1.43.0","1.44.0","1.46.0","1.47.0","1.48.0","1.49.0","1.5.0","1.50.0","1.51.0","1.52.0","1.53.0","1.54.0","1.55.0","1.56.0","1.57.0","1.58.0","1.59.0","1.6.0","1.60.0","1.61.0","1.62.0","1.63.0","1.64.0","1.65.0","1.66.0","1.67.0","1.68.0","1.69.0","1.7.0","1.70.0","1.71.0","1.72.0","1.73.0","1.74.0","1.75.0","1.76.0","1.77.0","1.78.0","1.79.0","1.8.0","1.80.0","1.81.0","1.82.0","1.83.0","1.84.0","1.84.1","1.85.0","1.85.1","1.86.0","1.86.1","1.87.0","1.88.0","1.89.0","1.89.1","1.9.0","1.9.1","1.90.0","1.91.0","1.92.0","1.93.0","1.94.0","1.95.0","1.95.1","1.96.0","1.96.1","1.97.0","1.98.0","1.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3gh4-cghq-f8v4/GHSA-3gh4-cghq-f8v4.json"}},{"package":{"name":"pydantic-ai","ecosystem":"PyPI","purl":"pkg:pypi/pydantic-ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0b1"},{"fixed":"2.27.1"}]}],"versions":["2.0.0","2.0.0b1","2.0.0b2","2.0.0b3","2.0.0b4","2.0.0b5","2.0.0b6","2.0.0b7","2.1.0","2.10.0","2.11.0","2.12.0","2.13.0","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.18.0","2.19.0","2.2.0","2.20.0","2.21.0","2.22.0","2.23.0","2.24.0","2.25.0","2.26.0","2.27.0","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3gh4-cghq-f8v4/GHSA-3gh4-cghq-f8v4.json"}},{"package":{"name":"pydantic-ai-slim","ecosystem":"PyPI","purl":"pkg:pypi/pydantic-ai-slim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.3.4"},{"fixed":"1.107.4"}]}],"versions":["0.3.4","0.3.5","0.3.6","0.3.7","0.4.0","0.4.1","0.4.10","0.4.11","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.4.8","0.4.9","0.5.0","0.5.1","0.6.0","0.6.1","0.6.2","0.7.0","0.7.1","0.7.2","0.7.3","0.7.4","0.7.5","0.7.6","0.8.0","0.8.1","1.0.0","1.0.0b1","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.10.0","1.100.0","1.101.0","1.102.0","1.103.0","1.104.0","1.105.0","1.106.0","1.107.0","1.107.1","1.107.2","1.11.0","1.11.1","1.12.0","1.13.0","1.14.0","1.14.1","1.15.0","1.16.0","1.17.0","1.18.0","1.19.0","1.2.0","1.2.1","1.20.0","1.21.0","1.22.0","1.23.0","1.24.0","1.25.0","1.25.1","1.26.0","1.27.0","1.28.0","1.29.0","1.3.0","1.30.0","1.30.1","1.31.0","1.32.0","1.33.0","1.34.0","1.35.0","1.36.0","1.37.0","1.38.0","1.39.0","1.39.1","1.4.0","1.40.0","1.41.0","1.42.0","1.43.0","1.44.0","1.46.0","1.47.0","1.48.0","1.49.0","1.5.0","1.50.0","1.51.0","1.52.0","1.53.0","1.54.0","1.55.0","1.56.0","1.57.0","1.58.0","1.59.0","1.6.0","1.60.0","1.61.0","1.62.0","1.63.0","1.64.0","1.65.0","1.66.0","1.67.0","1.68.0","1.69.0","1.7.0","1.70.0","1.71.0","1.72.0","1.73.0","1.74.0","1.75.0","1.76.0","1.77.0","1.78.0","1.79.0","1.8.0","1.80.0","1.81.0","1.82.0","1.83.0","1.84.0","1.84.1","1.85.0","1.85.1","1.86.0","1.86.1","1.87.0","1.88.0","1.89.0","1.89.1","1.9.0","1.9.1","1.90.0","1.91.0","1.92.0","1.93.0","1.94.0","1.95.0","1.95.1","1.96.0","1.96.1","1.97.0","1.98.0","1.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3gh4-cghq-f8v4/GHSA-3gh4-cghq-f8v4.json"}},{"package":{"name":"pydantic-ai-slim","ecosystem":"PyPI","purl":"pkg:pypi/pydantic-ai-slim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0b1"},{"fixed":"2.27.1"}]}],"versions":["2.0.0","2.0.0b1","2.0.0b2","2.0.0b3","2.0.0b4","2.0.0b5","2.0.0b6","2.0.0b7","2.1.0","2.10.0","2.11.0","2.12.0","2.13.0","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.18.0","2.19.0","2.2.0","2.20.0","2.21.0","2.22.0","2.23.0","2.24.0","2.25.0","2.26.0","2.27.0","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3gh4-cghq-f8v4/GHSA-3gh4-cghq-f8v4.json"}}],"references":[{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-3gh4-cghq-f8v4"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/pull/7357"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/commit/fe9dbed7b7ccf7e7128b5786886e4441f6f5594f"},{"type":"PACKAGE","url":"https://github.com/pydantic/pydantic-ai"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.27.1"}],"database_specific":{"cwe_ids":["CWE-212","CWE-532"],"github_reviewed":true,"github_reviewed_at":"2026-10-08T17:16:32Z","nvd_published_at":null,"severity":"LOW"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}