Information Disclosure Vulnerability in Ash Project AshAi by Ash Project
CVE-2026-82580

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82580?

An information disclosure vulnerability exists in Ash Project's AshAi software, where internal error messages are unintentionally exposed to chat users. When a tool in AshAi encounters an error, the system serializes the exception directly into the tool's output without any filtering. This may lead to sensitive system information, such as database constraints or validation messages, being sent back to the user. Users capable of manipulating tool arguments can trigger these errors and retrieve raw internal messages. The issue affects versions from 0.6.0 up to but not including 1.0.0, and has been addressed in subsequent updates that implement proper error handling to prevent sensitive data exposure.

Affected Version(s)

ash_ai 0.6.0 < 1.0.0

ash_ai bc2122f78fca6c11d8ec2b9ac53148ec17476460

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.