PT-2026-83666 · Unknown+1 · Ash Graphql+2

·

CVE-2026-75760

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash ai versions 0.1.0 through 0.9.x
Description In AshAi.Changes.Vectorize, a failure during the embedding provider call results in a changeset error that includes the raw error term. Because this error is not sanitized, it can disclose sensitive information to the user, such as the request URL, the provider response body, and the outbound Authorization header containing the provider API key. This occurs when AshJsonApi or AshGraphql render :invalid class errors back to the caller. An attacker can trigger this state by providing oversized or malformed vectorized content.
Recommendations Update ash ai to version 1.0.0 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75760
GHSA-P5CR-MMMF-6W39

Affected Products

Ash Graphql
Ashjsonapi
Ash-Aio