Infinite Loop Vulnerability in Ash Project's AI Tool
CVE-2026-82579

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82579?

The vulnerability in Ash Project's AI tool allows an attacker to exploit the system by creating conditions for an infinite loop during model interactions. This occurs when the tool_filters return an empty list after failing to validly process tool calls, leading the system to endlessly repeat the same request due to unbounded loop iterations. Such a scenario can be triggered by specially crafted input that reuses identifiers, thereby hindering model progression and exhausting system resources without termination. The issue affects versions from 0.6.0 up to, but not including, 1.0.0 and has been addressed in subsequent patches that treat empty outputs as terminal.

Affected Version(s)

ash_ai 0.6.0 < 1.0.0

ash_ai bc2122f78fca6c11d8ec2b9ac53148ec17476460 < 53325fdab90afab628c6a53232ef2a9001580bd9

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.