All 2 CVE vulnerabilities found in ash_ai, with AI-generated Chinese analysis, references, and POCs.
Vendor: ash-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-81315 | MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header CWE-346 | 7.4 | High | 2026-08-31 |
| CVE-2026-77956 | EEx template evaluation of prompt content in AshAi enables remote code execution CWE-94 | 10.0 | Critical | 2026-08-31 |
All 2 known CVE vulnerabilities affecting ash_ai with full Chinese analysis, references, and POCs where available.