Code Injection Vulnerability in Ash Project Ash Ai - Remote Execution Risk
CVE-2026-77956
What is CVE-2026-77956?
A significant code injection vulnerability exists in Ash Project's Ash Ai, enabling remote, unauthenticated clients to execute arbitrary Elixir code. This security flaw arises from improper evaluation of prompt content, allowing attacker-controlled input to be handled as executable code upon processing. Specifically, the use of EEx template evaluation permits potentially harmful commands to be run on the server without any form of authentication. The vulnerability is present in all versions from 0.1.0 up to but not including 1.0.0. A crucial fix has been implemented to ensure that only predefined templates are evaluated, effectively mitigating the risk of code injection.
Affected Version(s)
ash_ai 0.1.0 < 1.0.0
ash_ai 4aab131d40a0bd5a8cf0b3c4eaaa59d49565f3d1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
