Infinite Loop Vulnerability in Ash Project's AI Tool
CVE-2026-82579
What is CVE-2026-82579?
The vulnerability in Ash Project's AI tool allows an attacker to exploit the system by creating conditions for an infinite loop during model interactions. This occurs when the tool_filters return an empty list after failing to validly process tool calls, leading the system to endlessly repeat the same request due to unbounded loop iterations. Such a scenario can be triggered by specially crafted input that reuses identifiers, thereby hindering model progression and exhausting system resources without termination. The issue affects versions from 0.6.0 up to, but not including, 1.0.0 and has been addressed in subsequent patches that treat empty outputs as terminal.
Affected Version(s)
ash_ai 0.6.0 < 1.0.0
ash_ai bc2122f78fca6c11d8ec2b9ac53148ec17476460 < 53325fdab90afab628c6a53232ef2a9001580bd9
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
