ash_ai is vulnerable to Information Disclosure
53
Medium Risk
When a tool raises during execution, AshAi.ToolLoop serializes the raw exception message and returns it as tool-result content within the conversation and to the model provider. Sensitive internal details such as database table and column names, query fragments, and policy internals can leak through these messages. A user can steer the model into calling tools with arguments that trigger exceptions to extract that information. The fix routes raised tool errors through a safe formatter instead of exposing raw messages.
You are affected if you are using a version that falls within the vulnerable range and you expose tools whose exceptions can be triggered by untrusted chat input.
ash_ai is vulnerable to Information Disclosure in versions 0.6.0 - 0.8.2.
Upgrade the ash_ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.