---
cve: "CVE-2026-77956"
severity: "CRITICAL"
cvss: 10.0
epss: "60.6%"
vendor: "ash-project"
kev: false
exploited: false
published: "2026-08-31 01:16:49"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-02T10:25:40+02:00"
---

# CVE-2026-77956

> 10.0 CRITICAL · 🧪 PoC

## Beschreibung

Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.

AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> ... end form lets the prompt content be built from action arguments, so when a prompt action's text incorporates request data, that attacker-controlled text is compiled and run as an EEx template (Elixir source). Content such as  therefore executes on the server before any model request is made, requiring no authentication beyond reaching a prompt action. The fix stops evaluating function-supplied prompt content as EEx; only statically configured templates are evaluated.

This issue affects ash_ai: from 0.1.0 before 1.0.0.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- f72b14744996e71df6d73480d617d963f340597b (Commit)
- e9948254b5659c1143b73dc2f59f457931e64514 (Commit)

## Referenzen

- <https://github.com/ash-project/ash_ai/security/advisories/GHSA-2g59-hg7m-qc83>
- <https://cna.erlef.org/cves/CVE-2026-77956.html>
- <https://osv.dev/vulnerability/EEF-CVE-2026-77956>
- <https://github.com/ash-project/ash_ai/commit/e9948254b5659c1143b73dc2f59f457931e64514>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-77956) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
