Executive brief
AshAi is a library that exposes data-query capabilities to language models via tool calls. The aggregate query tool (min, max, sum, avg) bypasses per-actor field security policies, allowing callers to read sensitive fields like PII that are otherwise restricted. An actor can request aggregates on forbidden fields to extract their actual values, circumventing field-level access controls.
Technical details
The vulnerability is an authorization bypass in AshAi's aggregate read tool. The tool accepts aggregate functions (min, max, sum, avg) that build an Ash.Query.Aggregate over named fields, but field policy redaction—which normally blocks access to forbidden fields by replacing them with %Ash.ForbiddenField{}—does not apply to aggregate results. An attacker can request an aggregate (especially min/max, which return actual field values) on a field restricted by field policies; the tool only checked if the field is marked public, ignoring per-actor policy restrictions. The fix authorizes the aggregated field against resource field policies, either refusing the query or scoping results to visible rows. Affected versions: ash_ai 0.1.0 before 1.0.3.
Affected products
- AshAi AshAi 0.1.0 before 1.0.3
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fix released in version 1.0.3