PT-2026-83643 · Ash Ai · Ash-Aio

·

CVE-2026-77956

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v4.0

8.9

High

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions ash ai versions 0.1.0 through 0.9.x
Description An improper control of code generation allows a remote, unauthenticated client to execute arbitrary Elixir code. The AshAi.Actions.Prompt function evaluates prompt content using EEx.eval string/2. When a prompt action incorporates request data via the fn input, context -> ... end form, attacker-controlled text is compiled and executed as an EEx template (Elixir source) on the server before a model request is initiated.
Recommendations Update ash ai to version 1.0.0 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77956
GHSA-2G59-HG7M-QC83

Affected Products

Ash-Aio