PT-2026-83666 · Unknown+1 · Ash Graphql+2
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash ai versions 0.1.0 through 0.9.x
Description
In
AshAi.Changes.Vectorize, a failure during the embedding provider call results in a changeset error that includes the raw error term. Because this error is not sanitized, it can disclose sensitive information to the user, such as the request URL, the provider response body, and the outbound Authorization header containing the provider API key. This occurs when AshJsonApi or AshGraphql render :invalid class errors back to the caller. An attacker can trigger this state by providing oversized or malformed vectorized content.Recommendations
Update ash ai to version 1.0.0 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash Graphql
Ashjsonapi
Ash-Aio