ash_ai is vulnerable to Information Disclosure
71
High Risk
AshAi.Changes.Vectorize includes the raw embedding-provider error in a user-facing validation error when embedding generation fails. That error term can carry the outbound request, including the provider response body and the Authorization header holding the provider API key. Because the error is returned as an invalid-input class error, applications render it to callers, exposing credentials and internal request details to anyone able to submit create or update requests. The fix stops echoing the raw provider error into user-facing messages.
You are affected if you are using a version that falls within the vulnerable range and you use the vectorize change so that create or update input can trigger embedding-provider errors.
ash_ai is vulnerable to Information Disclosure in versions 0.1.0 - 0.8.2.
Upgrade the ash_ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.