Intel

AIKIDO-2026-305363

ai is vulnerable to Missing Authorization

Missing Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 2 days ago

42

Medium Risk

This Affects:

JSai
7.0.0 - 7.0.18
Fixed in 7.0.19
Are you affected? Scan for Free

TL;DR

In the ai package, tool-call parsing, execution, and approval collection resolve tool and approval names with plain property lookups, so a model- or client supplied name such as constructor, toString, valueOf, or __proto__ resolves to an inherited Object.prototype value instead of undefined. Such names can evade the intended "unknown tool" and "unconfigured approval" checks, letting a matching tool call proceed without the validation or human-in-the-loop approval the application configured. The fix replaces the lookups with Object.hasOwn own-property checks and null-prototype maps across tool-call parsing, execution, and approval collection.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and a tool name equal to a JavaScript Object.prototype member, such as constructor or toString, can reach tool-call parsing, execution, or approval collection.

Background info

ai is vulnerable to Missing Authorization in versions 7.0.0 - 7.0.18.

How to fix this

Upgrade the ai library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform