Ash-Project Ash Ai
7 known vulnerabilities in Ash-Project Ash Ai, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-78230 CVSS 6.0 medium AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that…
- CVE-2026-82580 CVSS 5.3 medium Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat…
- CVE-2026-82579 CVSS 6.0 medium Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's…
- CVE-2026-82564 CVSS 7.1 high Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to…
- CVE-2026-75760 CVSS 7.1 high Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and…
- CVE-2026-81315 CVSS 7.4 high Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding…
- CVE-2026-77956 CVSS 8.9 high Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to…