SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77956

HIGH · CVSS 8.9 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows remote, unauthenticated attackers to execute arbitrary Elixir code on servers running affected versions of ash_ai (from 0.1.0 to before 1.0.0) by manipulating prompt content in action arguments. This code injection can lead to severe consequences, including unauthorized access and control over server operations. Organizations using ash_ai should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77956
Severity
HIGH
CVSS
8.9
EPSS
0.19%

Original NVD Description

Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> ... end form lets the prompt content be built from action arguments, so when a prompt action's text incorporates request data, that attacker-controlled text is compiled and run as an EEx template (Elixir source). Content such as <%= System.cmd(...) %> therefore executes on the server before any model request is made, requiring no authentication beyond reaching a prompt action. The fix stops evaluating function-supplied prompt content as EEx; only statically configured templates are evaluated. This issue affects ash_ai: from 0.1.0 before 1.0.0.