VYPR

Vendor CVEs

Ash Project

All CVEs

83 total · sorted by risk
  • CVE-2026-77956HigAug 31, 2026
    risk 0.51cvss —epss 0.00

    Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input,…

  • CVE-2026-74837HigSep 1, 2026
    risk 0.50cvss —epss 0.01

    Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names. AshTypescript.FieldFormatter.convert_to_field_atom/2 in…

  • CVE-2026-81636HigAug 30, 2026
    risk 0.50cvss —epss 0.01

    Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read. AshGraphql.Graphql.Resolver.query_complexity/3 multiplies…

  • CVE-2025-48044HigOct 17, 2025
    risk 0.49cvss —epss 0.01

    Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.

  • CVE-2025-48043HigOct 10, 2025
    risk 0.49cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1.1 before 3.6.2.

  • CVE-2026-77850HigAug 31, 2026
    risk 0.48cvss —epss 0.00

    Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser. The relationship typeahead components AshAdmin.Components.Resource.RelationshipField and AshAdmin.Components.Resource.ManagedRela…

  • CVE-2026-67579HigAug 12, 2026
    risk 0.48cvss 7.4epss 0.01

    Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset…

  • CVE-2026-82722HigAug 31, 2026
    risk 0.47cvss —epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table and crash the entire node. Two LiveView event handlers interned atoms from unvalidated client input:…

  • CVE-2026-82673HigAug 31, 2026
    risk 0.47cvss —epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server. AshAdmin.Components.Resource.Form.consume_file_uploads/1 builds the destination as…

  • CVE-2026-75757HigAug 31, 2026
    risk 0.47cvss —epss 0.01

    Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state…

  • CVE-2026-82753HigSep 7, 2026
    risk 0.46cvss —epss 0.01

    Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by design. With Client ID Metadata Documents…

  • CVE-2026-82586HigSep 7, 2026
    risk 0.46cvss —epss 0.01

    Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The…

  • CVE-2026-82730HigSep 1, 2026
    risk 0.46cvss —epss 0.01

    Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in…

  • CVE-2026-77856HigSep 1, 2026
    risk 0.46cvss —epss 0.01

    Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names. resolve_typed_struct_field/2 in…

  • CVE-2026-82724HigAug 31, 2026
    risk 0.42cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce. AshPhoenix.LiveView.SubdomainHook.on_mount/4 attached a…

  • CVE-2026-81315HigAug 31, 2026
    risk 0.41cvss —epss 0.00

    Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Server, with the default allowed_origins:…

  • CVE-2026-78699HigAug 30, 2026
    risk 0.40cvss —epss 0.00

    Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data. …

  • CVE-2026-82564HigAug 31, 2026
    risk 0.39cvss —epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the…

  • CVE-2026-75760HigAug 31, 2026
    risk 0.39cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset…

  • CVE-2026-80223HigAug 30, 2026
    risk 0.39cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver authorizes each notification payload in…

  • CVE-2025-48042HigSep 7, 2025
    risk 0.39cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.

  • CVE-2026-81633MedAug 30, 2026
    risk 0.38cvss —epss 0.01

    Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resolve_node/2 decodes the client-supplied global ID with decode_relay_id/1, which…

  • CVE-2026-78693MedAug 30, 2026
    risk 0.38cvss —epss 0.01

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its error_handler to redact. In AshGraphql.Errors, each error is passed to the configured…

  • CVE-2026-82758MedSep 7, 2026
    risk 0.34cvss —epss 0.01

    Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server…

  • CVE-2026-82757MedSep 7, 2026
    risk 0.34cvss —epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 in…

  • CVE-2026-82756MedSep 7, 2026
    risk 0.34cvss —epss 0.01

    Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer…

  • CVE-2026-82755MedSep 7, 2026
    risk 0.34cvss —epss 0.01

    Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728 metadata endpoints in…

  • CVE-2026-82754MedSep 7, 2026
    risk 0.34cvss —epss 0.01

    Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in…

  • CVE-2026-82733MedSep 1, 2026
    risk 0.34cvss —epss 0.01

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a typed-controller route handler returns anything other than a…

  • CVE-2026-82732MedSep 1, 2026
    risk 0.34cvss —epss 0.01

    Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescript.TypedController.RequestHandler in lib/ash_typescript/typed_controller/request_…

  • CVE-2026-77950MedSep 1, 2026
    risk 0.34cvss —epss 0.01

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler does not match. apply_error_handler/3…

  • CVE-2026-82726MedAug 31, 2026
    risk 0.34cvss —epss 0.01

    Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a crafted Host header. AshPhoenix.Helpers.get_subdomain/2 stripped the root domain with String.replace(host,…

  • CVE-2026-86338MedSep 16, 2026
    risk 0.32cvss —epss 0.00

    Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used as a yes/no oracle to read a value the…

  • CVE-2026-78230MedSep 8, 2026
    risk 0.32cvss —epss 0.00

    AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned…

  • CVE-2026-78216MedSep 8, 2026
    risk 0.32cvss —epss 0.00

    AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on…

  • CVE-2026-82579MedAug 31, 2026
    risk 0.32cvss —epss 0.00

    Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then…

  • CVE-2026-93477MedSep 25, 2026
    risk 0.31cvss —epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments declared with public?: false are meant to be…

  • CVE-2026-82752MedSep 5, 2026
    risk 0.31cvss —epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's String.length/1, which counts Unicode…

  • CVE-2026-82747MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor. When a resource has an access_type :runtime read policy (a check evaluated per record rather than compiled to a filter), Ash.Policy.Authorizer decides each…

  • CVE-2026-82749MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records when the referenced parent field cannot be resolved. Loading a relationship whose filter references parent(...) resolves that expression…

  • CVE-2026-82746MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.update_many/4 runs as a single atomic statement (a data-layer update_many, for example a SQL MERGE) whenever…

  • CVE-2026-82745MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because neither enforced primary-key uniqueness on insert. Unlike a SQL data layer, whose unique primary-key constraint rejects…

  • CVE-2026-82742MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans multiple to-many relationships in memory. Ash.Filter.Runtime matches a filter against an in-memory record by first expanding the record into…

  • CVE-2026-82738MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 attribute. Ash.Type.UUIDv7.cast_input/2 accepts any well-formed UUID string, including non-version-7 UUIDs,…

  • CVE-2026-82737MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector with more than 65,535 elements. Ash.Vector.new/1 (lib/ash/vector.ex) encodes a vector as <<dim::unsigned-16,…

  • CVE-2026-82735MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint should have already rejected. Ash.Type.String.apply_constraints/2 (lib/ash/type/string.ex) evaluated the…

  • CVE-2026-81319MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption. AshCloak.Calculations.Decrypt…

  • CVE-2026-78228MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_error/4 runs the trigger's on_error action…

  • CVE-2026-78038MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across…

  • CVE-2026-77454MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing filter or sort. …

Page 1 of 2