VYPR

Vendor CVEs

Ash Project

All CVEs

82 total · sorted by risk
  • CVE-2026-75847MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the values of tracked sensitive? attributes in…

  • CVE-2026-55736MedJun 23, 2026
    risk 0.31cvss —epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code. Action arguments declared with…

  • CVE-2026-69659MedAug 9, 2026
    risk 0.29cvss 5.5epss 0.00

    Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in…

  • CVE-2026-82580MedAug 31, 2026
    risk 0.27cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the…

  • CVE-2024-49756MedOct 23, 2024
    risk 0.27cvss 5.3epss 0.01

    AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in certain very specific situations, it was possible for the policies of an update action to be skipped. This occurred only on "empty" update actions (no changing…

  • CVE-2026-82710LowSep 8, 2026
    risk 0.08cvss —epss 0.00

    Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_rules.search_docs searches Hex…

  • CVE-2026-82584LowSep 7, 2026
    risk 0.08cvss —epss 0.00

    Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt. mix igniter.install prints a confirmation panel (an anti-typosquatting safeguard)…

  • CVE-2026-82731LowSep 1, 2026
    risk 0.08cvss —epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials attached to it, to an unintended route or an external origin. The…

  • CVE-2026-82727LowAug 31, 2026
    risk 0.08cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted alongside a union form field leak into logs, crash reports and the dev error page. …

  • CVE-2026-82725LowAug 31, 2026
    risk 0.08cvss —epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, turning the returned rows into a boolean oracle over private related…

  • CVE-2026-81853LowAug 31, 2026
    risk 0.08cvss —epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality oracle over sensitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the composite-primary-key form (Base64 plus ETF) and returns the…

  • CVE-2026-82367LowAug 30, 2026
    risk 0.08cvss —epss 0.00

    Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.do_send/5 reads the resolved batch from the process dictionary via…

  • CVE-2026-81643LowAug 30, 2026
    risk 0.08cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see. In AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of a batch and filters it with…

  • CVE-2026-81638LowSep 7, 2026
    risk 0.07cvss —epss 0.00

    Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the first character…

  • CVE-2026-82748LowSep 1, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another, so an aggregate can run with policies that do not match the action it was authorized against. Ash.Actions.Aggregate groups aggregates by…

  • CVE-2026-82744LowSep 1, 2026
    risk 0.07cvss —epss 0.00

    Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controlling it raises, so a change meant to run does not. An Ash.Reactor change step can be gated by where validations that decide whether the change runs.…

  • CVE-2026-82743LowSep 1, 2026
    risk 0.07cvss —epss 0.00

    Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU while the framework waits for it. Ash.Actions.Read.AsyncLimiter.await_at_least_one/1 (lib/ash/actions/read/async_limiter.ex) waited for…

  • CVE-2026-82741LowSep 1, 2026
    risk 0.07cvss —epss 0.00

    Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an Ash.Type.Union value that uses storage: :map_with_tag, bypassing that member's validation and any tag-based authorization. For a union with…

  • CVE-2026-82740LowSep 1, 2026
    risk 0.07cvss —epss 0.00

    Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested {:array, {:array, type}} attribute, letting invalid input pass validation. Ash.Type.apply_constraints/3 (lib/ash/type/type.ex) handled the {:array,…

  • CVE-2026-82739LowSep 1, 2026
    risk 0.07cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its confirmation check. Ash.Resource.Validation.Confirm's atomic implementation (atomic/2 in…

  • CVE-2026-82736LowSep 1, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or match constraints. Ash.Type.CiString.apply_constraints/2 (lib/ash/type/ci_string.ex) validated the…

  • CVE-2026-82734LowSep 1, 2026
    risk 0.07cvss —epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal value that bypasses numeric bounds constraints or fails later operations on the value. Ash.Type.Decimal cast input through Ecto's decimal cast…

  • CVE-2026-81852LowAug 31, 2026
    risk 0.07cvss —epss 0.00

    Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without :csp_nonce_assign_key, AshAdmin.Router.ash_admin/2 defaulted the img, style,…

  • CVE-2026-81322LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts. …

  • CVE-2026-81318LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query, AshSql.AggregateQuery.add_single_aggs/5…

  • CVE-2026-81316LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary. …

  • CVE-2026-80227LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the…

  • CVE-2026-78691LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an…

  • CVE-2026-77846LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private or sensitive? embedded fields. …

  • CVE-2026-77831LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking,…

  • CVE-2026-70395LowAug 9, 2026
    risk 0.07cvss —epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_relationship is used with on_lookup: :relate…

  • CVE-2026-82681LowAug 31, 2026
    risk 0.06cvss —epss 0.00

    Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links. The Table, DataTable, and Show components built row-action URLs by raw string…

Page 2 of 2