VYPR

Ash

by Ash Project

hex: ash

Source repositories

CVEs (33)

  • CVE-2026-77956HigAug 31, 2026
    risk 0.51cvss —epss 0.00

    Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input,…

  • CVE-2025-48044HigOct 17, 2025
    risk 0.49cvss —epss 0.01

    Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.

  • CVE-2025-48043HigOct 10, 2025
    risk 0.49cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1.1 before 3.6.2.

  • CVE-2026-67579HigAug 12, 2026
    risk 0.48cvss 7.4epss 0.01

    Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset…

  • CVE-2026-81315HigAug 31, 2026
    risk 0.41cvss —epss 0.00

    Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Server, with the default allowed_origins:…

  • CVE-2026-82564HigAug 31, 2026
    risk 0.39cvss —epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the…

  • CVE-2026-75760HigAug 31, 2026
    risk 0.39cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset…

  • CVE-2025-48042HigSep 7, 2025
    risk 0.39cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.

  • CVE-2026-86338MedSep 16, 2026
    risk 0.32cvss —epss 0.00

    Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used as a yes/no oracle to read a value the…

  • CVE-2026-78230MedSep 8, 2026
    risk 0.32cvss —epss 0.00

    AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned…

  • CVE-2026-82579MedAug 31, 2026
    risk 0.32cvss —epss 0.00

    Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then…

  • CVE-2026-93477MedSep 25, 2026
    risk 0.31cvss —epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments declared with public?: false are meant to be…

  • CVE-2026-82752MedSep 5, 2026
    risk 0.31cvss —epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's String.length/1, which counts Unicode…

  • CVE-2026-82747MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor. When a resource has an access_type :runtime read policy (a check evaluated per record rather than compiled to a filter), Ash.Policy.Authorizer decides each…

  • CVE-2026-82749MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records when the referenced parent field cannot be resolved. Loading a relationship whose filter references parent(...) resolves that expression…

  • CVE-2026-82746MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.update_many/4 runs as a single atomic statement (a data-layer update_many, for example a SQL MERGE) whenever…

  • CVE-2026-82745MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because neither enforced primary-key uniqueness on insert. Unlike a SQL data layer, whose unique primary-key constraint rejects…

  • CVE-2026-82742MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans multiple to-many relationships in memory. Ash.Filter.Runtime matches a filter against an in-memory record by first expanding the record into…

  • CVE-2026-82738MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 attribute. Ash.Type.UUIDv7.cast_input/2 accepts any well-formed UUID string, including non-version-7 UUIDs,…

  • CVE-2026-82737MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector with more than 65,535 elements. Ash.Vector.new/1 (lib/ash/vector.ex) encodes a vector as <<dim::unsigned-16,…

Page 1 of 2