Current section
7 Advisories
Jump to
Current section
7 Advisories
AshAi aggregate tool can read field-policy-protected fields
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-78230.html
- https://github.com/ash-project/ash_ai/commit/2ba234b50946a3b8116190c8467f9f4dfa5edce7
- https://github.com/ash-project/ash_ai/commit/9c02de581625c342c9870a672830bff28c1d701e
- https://github.com/ash-project/ash_ai/security/advisories/GHSA-v5rw-36x5-r5vx
- https://hex.pm/packages/ash_ai
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
Affected Versions
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Affected Versions
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
Affected Versions
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
Affected Versions
MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header
Affected Versions
EEx template evaluation of prompt content in AshAi enables remote code execution
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
1 054
yesterday
1 614
last 7 days
8 882
all time
243 763