Origin Validation Error in AshAi MCP Server Affects Ash Project
CVE-2026-81315
What is CVE-2026-81315?
The vulnerability in the AshAi MCP Server allows a malicious web page to exploit an origin validation flaw, enabling DNS rebinding attacks. When the default setting permits nil origins, an attacker can craft a request that bypasses origin verification by manipulating the Host header and the X-Forwarded-Proto header. This serious flaw could allow unauthorized cross-site requests to the user's local MCP server, impacting data integrity and user security. To mitigate the risk, the latest patch restricts allowed origins to localhost by default and mandates explicit allowlisting for additional origins.
Affected Version(s)
ash_ai 0.8.0 < 1.0.0
ash_ai c94f0b17fbe252f68755ba512678586164ba6139 < 28af68d73134df0b8fb3aa6ab03e8fd795b07c21
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
