Impact
AshAi exposes a read tool that accepts aggregate operations over arbitrary named fields. The aggregate mechanism constructs an Ash.Query.Aggregate and returns raw aggregate values, bypassing the field‑policy redaction that normally replaces forbidden fields with a placeholder. As a result, an actor can obtain the actual value of a field that is protected by a per‑actor field policy, even if the field is marked public. This flaw allows sensitive PII or otherwise restricted data to be read via aggregate operations such as min, max, sum, or avg.
Affected Systems
Affected products include the open‑source AshAi tool from the ash‑project. All released versions from the initial 0.1.0 release up to and including 1.0.2 are vulnerable. Versions 1.0.3 and newer incorporate the fix that authorizes aggregate fields against the resource’s field policies and refuses or scopes requests when a field is not visible to the actor.
Risk and Exploitability
The vulnerability receives a CVSS score of 6.0, indicating moderate severity. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated or low‑privileged actor issuing a legitimate aggregate request via the language‑model tool call API. The attacker can therefore elevate data access privileges by retrieving protected field values that should be hidden, leading to data exposure.
OpenCVE Enrichment