Description
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error.

In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChanges in the :invalid class, which AshJsonApi and AshGraphql render back to the caller. The embedding client's error term is not sanitized, so it can carry the request URL, the provider response body, and, for HTTP clients that keep the request in the error struct, the outbound Authorization header with the provider API key. Failures are attacker-reachable via oversized or malformed vectorized content. The fix logs the raw error and returns a generic message.

This issue affects ash_ai: from 0.1.0 before 1.0.0.
Published: 2026-08-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when the AshAi vectorize function fails and the raw embedding‑provider error message is inserted directly into a user‑facing validation error. The unfiltered error string can contain the request URL, provider response body and, in some HTTP clients, the outbound Authorization header that holds the provider API key. This allows attackers to acquire secret credentials and other sensitive request information by triggering the failure path through oversized or malformed vectorized content. The flaw is a classic example of CWE‑209, data exposure through error messages.

Affected Systems

The issue affects the ash‑project ash_ai library for all releases from 0.1.0 up to, but excluding, 1.0.0. Versions earlier than 0.1.0 are not impacted, and releases 1.0.0 and later incorporate the fix that logs the raw error but returns a generic message.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, and the vulnerability is not currently listed in the CISA KEV catalog. EPSS data is not available, so the exact exploitation likelihood cannot be quantified, but the weakness remains exploitable by sending crafted content that forces a provider request to fail. The fix involves sanitizing the error before it reaches the API layer, which mitigates the risk of leaking credentials or request details to end users.

Generated by OpenCVE AI on August 31, 2026 at 02:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to ash_ai version 1.0.0 or later, which replaces the raw error with a generic message and logs the raw error internally.
  • If an immediate upgrade is not possible, adjust the application’s error‑handling pipeline to strip sensitive fields (e.g., request URL, Authorization header, provider response) from any Ash.Error.Changes.InvalidChanges before they are serialized to JSON for the client.
  • After applying the fix, rotate any API keys that could have been exposed in the logs and monitor for anomalous usage.

Generated by OpenCVE AI on August 31, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Description Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChanges in the :invalid class, which AshJsonApi and AshGraphql render back to the caller. The embedding client's error term is not sanitized, so it can carry the request URL, the provider response body, and, for HTTP clients that keep the request in the error struct, the outbound Authorization header with the provider API key. Failures are attacker-reachable via oversized or malformed vectorized content. The fix logs the raw error and returns a generic message. This issue affects ash_ai: from 0.1.0 before 1.0.0.
Title AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
First Time appeared Ash-project
Ash-project ash Ai
Weaknesses CWE-209
CPEs cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Ai
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-08-31T01:09:59.413Z

Reserved: 2026-08-30T23:15:02.367Z

Link: CVE-2026-75760

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T02:17:01.313

Modified: 2026-08-31T02:17:01.313

Link: CVE-2026-75760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T04:30:18Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information