ash_ai is vulnerable to Denial of Service (DoS)
60
Medium Risk
AshAi.ToolLoop recurses to process model tool calls, but when every returned tool call is filtered out as invalid or already processed the message list is unchanged and the empty result is not treated as terminal. The loop then re-sends byte-identical requests without advancing the conversation. With the supported :infinity iteration setting the exit check never triggers, causing an uncontrolled loop that exhausts resources. The fix terminates the loop when no unprocessed tool calls remain.
You are affected if you are using a version that falls within the vulnerable range and you run tool loops configured with the :infinity iteration setting.
ash_ai is vulnerable to Denial of Service (DoS) in versions 0.6.0 - 0.8.2.
Upgrade the ash_ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.