CVE-2026-78230
Deferred Deferred - Pending Action

Aggregate Field Policy Bypass in AshAi

Vulnerability report for CVE-2026-78230, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: EEF

Description

AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A tool caller could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate; min/max in particular return an actual field value. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The tool's existing check only required the field to be public, which is a separate axis from per-actor field-policy authorization. The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ash_ai ash From 0.1.0 (inc) to 1.0.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1220 The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AshAi allows language-model tool calls to execute Ash read actions. The vulnerability involves the read tool accepting aggregate operations (min, max, sum, avg) on fields. Field policies that redact forbidden fields during record retrieval do not apply to aggregate values, allowing unauthorized access to sensitive data like PII. The tool incorrectly only checked if a field was public, ignoring per-actor field policies.

Detection Guidance

This vulnerability is specific to AshAi and Ash framework implementations. Detection requires checking if ash_ai versions between 0.1.0 and 1.0.2 are installed and if language-model tool calls are using read actions with aggregate functions (min/max/sum/avg) on restricted fields.

Impact Analysis

An attacker with access to the tool could bypass field policies and read restricted data by using aggregate operations. This includes sensitive information protected by per-actor policies, even if the field is marked public. The impact is unauthorized data exposure, potentially violating privacy and security.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by allowing unauthorized access to sensitive personal data. GDPR requires strict data access controls, while HIPAA mandates protection of health information. The flaw enables bypassing these controls, risking legal penalties and data breaches.

Mitigation Strategies

Upgrade ash_ai to version 1.0.3 or later. Review field policies in Ash resources to ensure sensitive fields are properly restricted. Audit tool calls using read actions with aggregates to confirm they comply with field access policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78230. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart