Information Disclosure Vulnerability in Ash Project AshAi by Ash Project
CVE-2026-82580
What is CVE-2026-82580?
An information disclosure vulnerability exists in Ash Project's AshAi software, where internal error messages are unintentionally exposed to chat users. When a tool in AshAi encounters an error, the system serializes the exception directly into the tool's output without any filtering. This may lead to sensitive system information, such as database constraints or validation messages, being sent back to the user. Users capable of manipulating tool arguments can trigger these errors and retrieve raw internal messages. The issue affects versions from 0.6.0 up to but not including 1.0.0, and has been addressed in subsequent updates that implement proper error handling to prevent sensitive data exposure.
Affected Version(s)
ash_ai 0.6.0 < 1.0.0
ash_ai bc2122f78fca6c11d8ec2b9ac53148ec17476460
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
