Sensitive Information Disclosure in Ash Project's Ash_AI
CVE-2026-75760

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-75760?

A vulnerability in Ash_AI allows for the disclosure of sensitive information, including provider request states and credentials, during user-facing validation errors. Specifically, when an embedding provider call fails in the AshAi.Changes.Vectorize function, the resulting error message may expose critical details such as the request URL, provider response body, and even the outbound Authorization header containing the provider API key. This occurs because the error message generation does not sanitize the raw error term, making it accessible to attackers through oversized or malformed content. The vulnerability affects versions of Ash_AI before 1.0.0, and the fix involves logging the error details securely and returning a generic error message to users.

Affected Version(s)

ash_ai 0.1.0 < 1.0.0

ash_ai 5334edc73a007f0629661761d6a75796f2fc0004 < 088a2562e16d65f36cec178070de683636479f58

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.