VYPR

ash_lua

by Ash Project

CVEs (1)

  • CVE-2026-82586HigSep 7, 2026
    risk 0.46cvss epss

    Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The…