Junglewise Threat Intelligence

CVE-2026-81315: ash-project ash_ai origin validation bypass in MCP server

CVE-2026-81315 · Severity: info · Published 2026-08-31

Technologies: Ash-Project Ash Ai. Vendors: Ash-Project.

Executive brief

ash_ai is a library that provides an MCP (Model Context Protocol) server for AI integration. A flaw in its origin validation allows attackers to bypass DNS-rebinding protection through malicious web pages, enabling unauthorized cross-site requests to users' local MCP servers with the user's credentials. This could allow attackers to manipulate local AI operations or extract sensitive information.

Technical details

The vulnerability is an origin validation error in AshAi.Mcp.Server's origin_allowed?/3 function. With default configuration (allowed_origins: nil), the check compares uri.host against conn.host and validates the forwarded scheme is https, but both values are attacker-controlled: the Host header and raw X-Forwarded-Proto header are used without verifying a trusted proxy. Under DNS rebinding, an attacker's origin and matching host are sent by the browser, and JavaScript can set X-Forwarded-Proto: https, causing the validation to pass even without actual TLS or proxy involvement. The fix restricts default origins to localhost only, requiring explicit allowlist configuration for other origins.

Affected products

  • ash-project ash_ai 0.8.0 before 1.0.0

Timeline

  • 2026-08-31: disclosed

References

Related threats