ash_ai
Structured outputs, vectorization and tool calling for your Ash application
Activity
- Latest release
- 5d ago
- Total releases
- 42
- Cadence
- ~5 days
- Last 12 months
- 17
Reach
- Downloads
- 225.9k
- Stars
- 189
Details
- License
- MIT
- First release
- May 14, 2025
| Version | Released | |
|---|---|---|
1.0.3
patch
|
1.0.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.0.2
patch
1 CVE
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev |
1.0.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.0.1
patch
1 CVE
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev |
1.0.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.0.0
major
1 CVE
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev |
1.0.0
major
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.8.2
patch
7 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81315
EEF-CVE-2026-81315
GHSA-c92r-f3rr-q49h
Aug 31, 2026
MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header
Critical
Network
Low
None
SummaryOrigin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In This issue affects ash_ai: from 0.8.0 before 1.0.0. Affected versions
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.8.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.8.1
patch
7 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81315
EEF-CVE-2026-81315
GHSA-c92r-f3rr-q49h
Aug 31, 2026
MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header
Critical
Network
Low
None
SummaryOrigin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In This issue affects ash_ai: from 0.8.0 before 1.0.0. Affected versions
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.8.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.8.0
minor
7 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81315
EEF-CVE-2026-81315
GHSA-c92r-f3rr-q49h
Aug 31, 2026
MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header
Critical
Network
Low
None
SummaryOrigin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In This issue affects ash_ai: from 0.8.0 before 1.0.0. Affected versions
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.8.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.3
patch
6 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.7.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.2
patch
6 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.7.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.1
patch
6 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.7.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.0
minor
6 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.7.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.6.1
patch
6 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.6.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.6.0
minor
6 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82580
EEF-CVE-2026-82580
GHSA-5747-6mpw-6m9c
Aug 31, 2026
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Medium
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82579
EEF-CVE-2026-82579
GHSA-rcx7-x2w5-mmc2
Aug 31, 2026
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
High
Network
Low
Low
None
SummaryLoop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82564
EEF-CVE-2026-82564
GHSA-jg86-xh36-h5xc
Aug 31, 2026
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
High
Network
Low
Low
None
SummaryAuthorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an In This issue affects ash_ai: from 0.6.0 before 1.0.0. Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.6.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.5.0
minor
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.5.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.4.0
minor
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.4.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.3.0
minor
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.3.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.14
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.14
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.13
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.13
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.12
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.12
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.11
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.11
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.10
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.10
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.9
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.9
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.8
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.8
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.7
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.7
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.6
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.6
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.5
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.4
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.3
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.2
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.1
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.0
minor
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.11
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.11
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.10
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.10
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.9
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.9
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.8
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.8
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.7
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.7
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.6
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.6
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.5
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.4
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.3
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.1
patch
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.0
initial
3 CVEs
CVE-2026-78230
EEF-CVE-2026-78230
GHSA-v5rw-36x5-r5vx
Sep 08, 2026
AshAi aggregate tool can read field-policy-protected fields
High
Network
Low
Low
None
SummaryAshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type ( Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ConfigurationsReachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 29 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75760
EEF-CVE-2026-75760
GHSA-p5cr-mmmf-6w39
Aug 31, 2026
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
High
Network
Low
Low
None
SummaryGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In This issue affects ash_ai: from 0.1.0 before 1.0.0. ConfigurationsThe application exposes a resource with Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77956
EEF-CVE-2026-77956
GHSA-2g59-hg7m-qc83
Aug 31, 2026
EEx template evaluation of prompt content in AshAi enables remote code execution
Critical
Local
Low
None
None
SummaryImproper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
This issue affects ash_ai: from 0.1.0 before 1.0.0. Affected versions
0.1.0
0.1.1
0.1.10
0.1.11
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
+ 26 more Show less
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
Fixed in
1.0.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.0
initial
Dependencies (11)
+ 3 more
Changelog
|