Intel

AIKIDO-2026-87580

ash_ai is vulnerable to Information Disclosure

Information DisclosureCVE-2026-75760 Published Yesterday

71

High Risk

This Affects:

ELIXIRash_ai
0.1.0 - 0.8.2
Fixed in 1.0.0
Are you affected? Scan for Free

TL;DR

AshAi.Changes.Vectorize includes the raw embedding-provider error in a user-facing validation error when embedding generation fails. That error term can carry the outbound request, including the provider response body and the Authorization header holding the provider API key. Because the error is returned as an invalid-input class error, applications render it to callers, exposing credentials and internal request details to anyone able to submit create or update requests. The fix stops echoing the raw provider error into user-facing messages.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the vectorize change so that create or update input can trigger embedding-provider errors.

Background info

ash_ai is vulnerable to Information Disclosure in versions 0.1.0 - 0.8.2.

How to fix this

Upgrade the ash_ai library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform