SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75760

HIGH · CVSS 7.1 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in AshAi allows for the exposure of sensitive information, including provider request state and credentials, through unsanitized error messages generated during failed embedding provider calls. Attackers can exploit this flaw by submitting oversized or malformed vectorized content, potentially revealing critical data such as the request URL and API keys. Organizations using ash_ai versions from 0.1.0 to before 1.0.0 should prioritize patching this issue to mitigate the risk of credential leakage and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75760
Severity
HIGH
CVSS
7.1
EPSS
0.28%

Original NVD Description

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChanges in the :invalid class, which AshJsonApi and AshGraphql render back to the caller. The embedding client's error term is not sanitized, so it can carry the request URL, the provider response body, and, for HTTP clients that keep the request in the error struct, the outbound Authorization header with the provider API key. Failures are attacker-reachable via oversized or malformed vectorized content. The fix logs the raw error and returns a generic message. This issue affects ash_ai: from 0.1.0 before 1.0.0.