CVE-2026-78230: AshAi aggregate tool can read field-policy-protected fields
AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value.
Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A tool caller could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate; min/max in particular return an actual field value. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The tool's existing check only required the field to be public, which is a separate axis from per-actor field-policy authorization.
The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible.
This issue affects ashai: from 0.1.0 before 1.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ash_aito a version that resolves this vulnerability.Fixed in 1.0.3 - Compensating control
Restrict tool access so the language-model cannot issue Ash read actions via the AshAi aggregate tool (min/max/sum/avg) until ash_ai is upgraded to 1.0.3, preventing aggregation over per-actor field-policy-protected fields (e.g., sensitive PII).
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using ash_ai versions from 0.1.0 before 1.0.3 are affected when Ash read actions are exposed through language-model tool calls. Exposure is relevant where a field is public but restricted for particular actors by an Ash field policy.
What must an attacker be able to do?
The attacker must be able to invoke the AshAi read tool as an actor whose field policy forbids access to a target field. They can request an aggregate such as min or max over that named field; those aggregates can return an actual protected field value.
Are protected fields safe if they are marked public?
No. The vulnerable tool check required only that the field be public, which does not account for per-actor field-policy authorization. Fields marked public but restricted by field policies, including sensitive PII, can be exposed through aggregates.
How can this be remediated?
Upgrade to ash_ai 1.0.3 or later. The fix authorizes the aggregated field using the resource field policies and refuses access or scopes results to rows where the actor may view the field.