Origin Validation Error in AshAi MCP Server Affects Ash Project
CVE-2026-81315

7.4HIGH

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-81315?

The vulnerability in the AshAi MCP Server allows a malicious web page to exploit an origin validation flaw, enabling DNS rebinding attacks. When the default setting permits nil origins, an attacker can craft a request that bypasses origin verification by manipulating the Host header and the X-Forwarded-Proto header. This serious flaw could allow unauthorized cross-site requests to the user's local MCP server, impacting data integrity and user security. To mitigate the risk, the latest patch restricts allowed origins to localhost by default and mandates explicit allowlisting for additional origins.

Affected Version(s)

ash_ai 0.8.0 < 1.0.0

ash_ai c94f0b17fbe252f68755ba512678586164ba6139 < 28af68d73134df0b8fb3aa6ab03e8fd795b07c21

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.