{"data":{"id":"a4284793-cd40-4852-b38a-d822ba6c609b","title":"CVE-2026-77956: Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthentic","summary":"A code injection vulnerability in ash_ai allows unauthenticated attackers to execute arbitrary Elixir code (a programming language) on a server. The vulnerability occurs because the system uses EEx.eval_string/2 (a template evaluator that treats input as code) to process user-supplied prompt text, meaning an attacker can embed malicious commands that get executed before any AI model even processes the request.","solution":"The fix stops evaluating function-supplied prompt content as EEx; only statically configured templates are evaluated. This issue affects ash_ai versions from 0.1.0 before 1.0.0, meaning users should upgrade to version 1.0.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77956","publishedAt":"2026-08-31T01:16:49.563Z","cveId":"CVE-2026-77956","cweIds":["CWE-94"],"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["ash_ai"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-31T01:16:49.563Z","capecIds":["CAPEC-242"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}