以下是该漏洞描述的中文翻译: ash_ai 中通过用户可控 Key 实现的授权绕过漏洞 Ash AI 中的授权绕过漏洞允许配置了身份(identity)的工具调用者更新或删除其未曾识别的记录,甚至可能影响表中的每一行。 漏洞详情: 在 中, 函数直接使用原始的工具参数构建更新/删除过滤器: ,并传递给 。由于 Map 的值被解析为谓词表达式(predicate expression)而非字面量(literal),调用者可以发送形如 的参数,结合 和 ,将写操作重定向到一个其未曾识别的记录。如果省略了某个 key,则
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_ai | 0.6.0 ~ 1.0.0 |
cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_ai | bc2122f78fca6c11d8ec2b9ac53148ec17476460 ~ 87f616d5bfbf7af43346f0701ae17f853789a602 |
cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77956 | 10.0 CRITICAL | EEx template evaluation of prompt content in AshAi enables remote code execution |
| CVE-2026-77850 | 8.4 HIGH | Stored XSS in AshAdmin relationship typeahead via unescaped label_field content |
| CVE-2026-82673 | 8.3 HIGH | Path traversal in AshAdmin file uploads via unsanitized client filename |
| CVE-2026-82722 | 8.3 HIGH | AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node D |
| CVE-2026-75757 | 8.3 HIGH | AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a |
| CVE-2026-81315 | 7.4 HIGH | MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header |
| CVE-2026-75760 | 7.1 HIGH | AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a us |
| CVE-2026-82579 | 6.0 MEDIUM | AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of |
| CVE-2026-82580 | 5.3 MEDIUM | AshAi echoes raw tool exception messages into the conversation, disclosing internal detail |
| CVE-2026-81853 | 2.3 LOW | AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attrib |
| CVE-2026-81852 | 2.1 LOW | AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass |
| CVE-2026-82681 | 2.0 LOW | Query-parameter injection in AshAdmin row-action links via unencoded string primary keys |
No comments yet