pydantic-ai-slim is vulnerable to Information Disclosure
23
Low Risk
Pydantic AI's OpenTelemetry instrumentation lets InstrumentationSettings(include_content=False) exclude message content from exported telemetry, but exception events, the span error status description, and the model_request_parameters attribute keep exporting that content regardless of the setting. A tool retry, a chained exception after exhausted retries, or a model, embedding, or image-generation provider error can quote prompts, tool arguments, or the provider's error body, and the request attribute serializes the agent's full instructions and prompted-output template. The fix withholds the exception message and stack trace, the status description, and the instruction and template content when include_content is false, keeping only structural information.
You are affected if you are using a version that falls within the vulnerable range and you set InstrumentationSettings(include_content=False) to exclude message content from telemetry.
pydantic-ai-slim is vulnerable to Information Disclosure in versions 0.3.4 - 1.107.5 and 2.0.0 - 2.43.0.
Upgrade the pydantic-ai-slim and/or the pydantic-ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.