AshAi 将 Ash 的读取操作暴露给语言模型的工具调用。其中的“read”工具接受一种聚合结果类型(min、max、sum、avg),它会针对指定字段构建一个临时的 ,并返回其原始值。 虽然 Ash 的字段策略(field policies)会在返回的记录中遮蔽(redact)被禁止的字段(将其替换为 ),但这种遮蔽机制并不适用于聚合计算后的值。因此,工具调用方可以通过请求某个字段作为聚合值,来读取其当前角色(actor)的字段策略所禁止访问的字段;尤其是 min/max 聚合会直接返回该字段的实际值。这涵盖了
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ash-project | ash_ai | 0.1.0< 1.0.3 |
affected |
2ba234b50946a3b8116190c8467f9f4dfa5edce7< 9c02de581625c342c9870a672830bff28c1d701e |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_ai | 0.1.0 ~ 1.0.3 |
cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_ai | 2ba234b50946a3b8116190c8467f9f4dfa5edce7 ~ 9c02de581625c342c9870a672830bff28c1d701e |
cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78216 | 6.0 MEDIUM | AshLua eval read operations can read field-policy-protected fields via aggregates |
| CVE-2026-82710 | 2.3 LOW | Terminal escape sequence injection in mix usage_rules.search_docs via package documentatio |
No comments yet