VYPR

ash_phoenix

by Ash Project

CVEs (1)

  • CVE-2026-82725LowAug 31, 2026
    risk 0.08cvss epss

    Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, turning the returned rows into a boolean oracle over private related…