ash_ai Vulnerabilities Expose Critical Risks in Elixir Framework

ash_ai Vulnerabilities Expose Critical Risks in Elixir Framework

First seen 31 Aug 2026, 17:01 UTC Tech.YahooForkast.Newsgithub.com 70.5

Article Content

Browse articles
ThreatCluster

On August 30, 2026, maintainer zachdaniel disclosed a cluster of six vulnerabilities in ash_ai, an LLM toolbox extension for the Elixir-based Ash Framework. This marks the first coordinated security disclosure in the Elixir/Ash ecosystem. The most critical vulnerability, CVE-2026-77956 (CVSS 8.9), allows remote code execution via user-provided prompts treated as executable code. Other vulnerabilities include CVE-2026-81315 (CVSS 7.4), which enables origin validation bypass, and CVE-2026-82564 (CVSS 7.1), allowing authorization bypass through nested JSON parsing. Additional issues include API key leakage (CVE-2026-75760), an infinite loop (CVE-2026-82579), and database schema disclosure (CVE-2026-82580). All vulnerabilities were discovered by researcher PJUllrich using LLM-assisted security research. The vulnerabilities were addressed in version 1.0.0 of ash_ai, released on the same day as the disclosure.

Key Points: • Six critical vulnerabilities disclosed in ash_ai, affecting the Elixir/Ash ecosystem. • CVE-2026-77956 allows remote code execution via user-provided prompts. • All vulnerabilities were patched in version 1.0.0 released on August 30, 2026.

Timeline

2026-08-30
Vulnerabilities disclosed
Maintainer zachdaniel disclosed six vulnerabilities in ash_ai, marking the first coordinated security disclosure in the Elixir/Ash ecosystem.
Forkast.News
2026-08-31
CVE-2026-75760 published
CVE-2026-75760, which leaks API keys through error messages, was published.
Forkast.News
2026-08-31
CVE-2026-82580 published
CVE-2026-82580, which discloses database schema information, was published.
Forkast.News
2026-08-31
CVE-2026-82564 published
CVE-2026-82564, allowing authorization bypass, was published.
Forkast.News
2026-08-31
CVE-2026-82579 published
CVE-2026-82579, which causes an infinite loop in tool orchestration, was published.
Forkast.News
2026-08-31
CVE-2026-77956 published
CVE-2026-77956, the most critical RCE vulnerability, was published.
Forkast.News
2026-08-31
CVE-2026-81315 published
CVE-2026-81315, which allows origin validation bypass, was published.
Forkast.News