EEF-CVE-2026-78230

    Dashboard / Vulnerabilities / EEF-CVE-2026-78230

    EEF-CVE-2026-78230

    Published: 8 Sept 2026Last Modified: 8 Sept 2026

    Summary: AshAi aggregate tool can read field-policy-protected fields

    Details: ## Summary AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (`min`, `max`, `sum`, `avg`) that builds an ad-hoc `Ash.Query.Aggregate` over a named field and returns its raw value. Ash field policies redact forbidden fields on returned records (replacing them with `%Ash.ForbiddenField{}`), but that redaction does not apply to aggregate values. A tool caller could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate; `min`/`max` in particular return an actual field value. This includes fields that are `public? true` but restricted per-actor by a field policy, such as sensitive PII. The tool's existing check only required the field to be public, which is a separate axis from per-actor field-policy authorization. The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_ai: from 0.1.0 before 1.0.3. ## Configurations Reachable only when an application exposes an AshAi read tool over a resource whose field policies restrict a field that the calling actor can still name as an aggregate (for example a `public? true` but field-policy-protected attribute).

    Affected packages

    Package

    Name: ash_ai

    Purl: pkg:hex/ash_ai

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.1.0
    Fixed -1.0.3

    Affected versions

    0.1.0
    0.1.1
    0.1.10
    0.1.11
    0.1.3
    0.1.4
    0.1.5
    0.1.6
    0.1.7
    0.1.8
    0.1.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    EEF-CVE-2026-78230 | CVE-DB