Description
AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value.

Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A tool caller could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate; min/max in particular return an actual field value. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The tool's existing check only required the field to be public, which is a separate axis from per-actor field-policy authorization.

The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible.

This issue affects ash_ai: from 0.1.0 before 1.0.3.
Published: 2026-09-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure via Aggregate Reads
Action: Patch Critical
AI Analysis

Impact

AshAi exposes a read tool that accepts aggregate operations over arbitrary named fields. The aggregate mechanism constructs an Ash.Query.Aggregate and returns raw aggregate values, bypassing the field‑policy redaction that normally replaces forbidden fields with a placeholder. As a result, an actor can obtain the actual value of a field that is protected by a per‑actor field policy, even if the field is marked public. This flaw allows sensitive PII or otherwise restricted data to be read via aggregate operations such as min, max, sum, or avg.

Affected Systems

Affected products include the open‑source AshAi tool from the ash‑project. All released versions from the initial 0.1.0 release up to and including 1.0.2 are vulnerable. Versions 1.0.3 and newer incorporate the fix that authorizes aggregate fields against the resource’s field policies and refuses or scopes requests when a field is not visible to the actor.

Risk and Exploitability

The vulnerability receives a CVSS score of 6.0, indicating moderate severity. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated or low‑privileged actor issuing a legitimate aggregate request via the language‑model tool call API. The attacker can therefore elevate data access privileges by retrieving protected field values that should be hidden, leading to data exposure.

Generated by OpenCVE AI on September 8, 2026 at 18:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ash_ai to version 1.0.3 or newer.
  • Ensure that aggregate tool calls are only allowed for actors with explicit field‑policy permissions; consider disabling them for external or untrusted callers.
  • Validate that aggregates against sensitive fields are rejected or correctly scoped by reviewing audit logs and performing tests with representative actor roles.

Generated by OpenCVE AI on September 8, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A tool caller could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate; min/max in particular return an actual field value. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The tool's existing check only required the field to be public, which is a separate axis from per-actor field-policy authorization. The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3.
Title AshAi aggregate tool can read field-policy-protected fields
First Time appeared Ash-project
Ash-project ash Ai
Weaknesses CWE-1220
CPEs cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Ai
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-08T17:33:57.604Z

Reserved: 2026-08-31T00:45:02.439Z

Link: CVE-2026-78230

cve-icon Vulnrichment

Updated: 2026-09-08T17:33:52.342Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T17:18:30.840

Modified: 2026-09-08T19:29:09.680

Link: CVE-2026-78230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:00:11Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control