PT-2026-83669 · Ash Ai · Ash-Aio
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash ai versions 0.6.0 through 0.9.x
Description
In
AshAi.ToolLoop and AshAi.Tools, exceptions raised during tool execution are serialized verbatim using Exception.message/1 into the tool-result content. This content is appended to the conversation and sent back to the model, which typically relays it to the user. Because no filtering occurs, internal data such as database constraint messages, adapter errors, query fragments, and policy or validation internals are disclosed. A chat user can trigger this by providing tool arguments that lead to a code path that raises an exception.Recommendations
Update ash ai to version 1.0.0 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash-Aio