CVE-2026-82580: AshAi echoes raw tool exception messages into the conversation, disclosing internal details
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ashai discloses internal error text to chat users.
In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:toolresult, ...} stream event, and sent back to the model, which typically relays it to the user. No filtering happened first, so anything raised inside a tool callback or lifecycle hook (database constraint messages, adapter errors, query fragments, policy or validation internals) was echoed as-is. A chat user who can steer tool arguments into a raising code path receives the raw internal text. The fix routes raised tool errors through the same safe formatter used for other tool errors.
This issue affects ashai: from 0.6.0 before 1.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ash-project ash_aito a version that resolves this vulnerability.Fixed in 1.0.0 - Configuration
Route raised tool errors through the safe formatter used for other tool errors instead of serializing Exception.message/1 verbatim into the {:tool_result, ...} stream.
AshAi.ToolLoop / AshAi.Tools tool error serialization/formatting = safe formatter (use safe formatter for raised tool errors)