VYPR

Ash

by Ash Project

hex: ash

Source repositories

CVEs (7)

  • CVE-2026-67579HigAug 12, 2026
    risk 0.49cvss epss

    Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset…

  • CVE-2025-48044HigOct 17, 2025
    risk 0.49cvss epss 0.01

    Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from 3.6.3 before 3.7.1.

  • CVE-2025-48043HigOct 10, 2025
    risk 0.49cvss epss 0.00

    Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2. This issue affects ash: from…

  • CVE-2025-48042HigSep 7, 2025
    risk 0.39cvss epss 0.00

    Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex…

  • CVE-2026-69659MedAug 9, 2026
    risk 0.31cvss epss 0.00

    Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in…

  • CVE-2026-55736MedJun 23, 2026
    risk 0.31cvss epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code. Action arguments declared with…

  • CVE-2026-70395LowAug 9, 2026
    risk 0.07cvss epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_relationship is used with on_lookup: :relate…