Junglewise Threat Intelligence

CVE-2026-75760: ash-project ash_ai sensitive information disclosure in error messages

CVE-2026-75760 · Severity: info · CVSS 0 · Published 2026-08-31

Technologies: Ash-Project Ash Ai. Vendors: Ash-Project.

Executive brief

AshAi is a library that integrates AI embedding providers into Ash applications. When an embedding provider call fails, the system was returning detailed error messages to users that inadvertently exposed sensitive information, including API keys, request URLs, and provider response details. An attacker can trigger failures by sending malformed or oversized content, causing the system to leak credentials and internal request state to anyone viewing the error message.

Technical details

The vulnerability exists in AshAi.Changes.Vectorize, where failed embedding provider calls generate changeset errors that include the raw error term via string interpolation (An error occurred while generating embeddings: #{inspect(error)}). These error messages are rendered back to API clients by AshJsonApi and AshGraphql without sanitization. The embedding client's error struct can contain the request URL, provider response body, and—depending on the HTTP client implementation—the outbound Authorization header containing the provider API key. Attackers can trigger failures by submitting oversized or malformed vectorized content. The fix logs the raw error server-side and returns a generic, non-revealing error message to clients.

Affected products

  • ash-project ash_ai 0.1.0 to before 1.0.0

Timeline

  • 2026-08-31: disclosed

References

Related threats