Authorization Bypass Vulnerability in Ash Project's Ash AI
CVE-2026-82564
What is CVE-2026-82564?
The vulnerability in Ash Project's Ash AI allows unauthorized users to perform update or destroy operations on database records. This occurs due to the faulty construction of update/destroy filters directly from user-provided arguments, making it possible for attackers to manipulate the records without proper identification. An attacker could exploit this by sending crafted requests that omit necessary identity keys, resulting in arbitrary records being targeted. The issue has been addressed in versions following 1.0.0, which enforce stricter validation on identity values to mitigate this risk.
Affected Version(s)
ash_ai 0.6.0 < 1.0.0
ash_ai bc2122f78fca6c11d8ec2b9ac53148ec17476460 < 87f616d5bfbf7af43346f0701ae17f853789a602
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
