CVE-2026-78230: AshAi aggregate tool can read field-policy-protected fields

Published Sep 8, 2026
·
Updated

AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value.

Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A tool caller could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate; min/max in particular return an actual field value. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The tool's existing check only required the field to be public, which is a separate axis from per-actor field-policy authorization.

The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible.

This issue affects ashai: from 0.1.0 before 1.0.3.

Affected Software

1 affected component
ash_ai>0.1.0<=1.0.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ash_ai to a version that resolves this vulnerability.

    Fixed in 1.0.3
  2. Compensating control

    Restrict tool access so the language-model cannot issue Ash read actions via the AshAi aggregate tool (min/max/sum/avg) until ash_ai is upgraded to 1.0.3, preventing aggregation over per-actor field-policy-protected fields (e.g., sensitive PII).

Event History

Sep 8, 2026
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
DescriptionWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using ash_ai versions from 0.1.0 before 1.0.3 are affected when Ash read actions are exposed through language-model tool calls. Exposure is relevant where a field is public but restricted for particular actors by an Ash field policy.

2

What must an attacker be able to do?

The attacker must be able to invoke the AshAi read tool as an actor whose field policy forbids access to a target field. They can request an aggregate such as min or max over that named field; those aggregates can return an actual protected field value.

3

Are protected fields safe if they are marked public?

No. The vulnerable tool check required only that the field be public, which does not account for per-actor field-policy authorization. Fields marked public but restricted by field policies, including sensitive PII, can be exposed through aggregates.

4

How can this be remediated?

Upgrade to ash_ai 1.0.3 or later. The fix authorizes the aggregated field using the resource field policies and refuses access or scopes results to rows where the actor may view the field.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203