Vulnerabilities in ash-project
83 resultsVexday analysis
Ash Project apresenta um perfil de risco baixo com apenas 7 CVEs catalogadas, nenhuma atualmente sob exploração ativa. A vulnerabilidade dominante é CWE-863 (Uso Impróprio de Autorização), sem críticas de severidade máxima registradas. O risco é moderado dado 1 publicação nos últimos 90 dias, indicando manutenção ativa do projeto.
CVE-2026-82733MEDIUMRoute handler return value echoed into AshTypescript error responseEPSS 0.3%CVE-2026-77950MEDIUMRPC error handler fails open in AshTypescript, disclosing unredacted errorsEPSS 0.3%CVE-2026-77856HIGHUnbounded atom creation from typed struct field names in AshTypescript field selectorEPSS 0.3%CVE-2026-82564HIGHIdentity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified recordsEPSS 0.3%CVE-2026-81852LOWAshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypassEPSS 0.3%CVE-2026-82584LOWTerminal escape sequence injection in the mix igniter.install confirmation prompt via package metadataEPSS 0.3%CVE-2026-82726MEDIUMAshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenantEPSS 0.3%CVE-2026-81633MEDIUMUnhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segmentEPSS 0.3%CVE-2026-75757HIGHAshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomainEPSS 0.3%CVE-2026-78693MEDIUMIncomplete redaction re-attaches the original error path in AshGraphql, leaking internal field namesEPSS 0.3%CVE-2026-82731LOWUnescaped path parameters in AshTypescript generated TypeScript client allow request redirectionEPSS 0.3%CVE-2026-82730HIGHAuthorization-redacted field values disclosed through AshTypescript result normalizationEPSS 0.3%CVE-2026-75760HIGHAshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing errorEPSS 0.3%CVE-2026-77850HIGHStored XSS in AshAdmin relationship typeahead via unescaped label_field contentEPSS 0.3%CVE-2026-82579MEDIUMAshAi tool loop never terminates when all tool calls are filtered out, enabling denial of serviceEPSS 0.3%CVE-2026-82681LOWQuery-parameter injection in AshAdmin row-action links via unencoded string primary keysEPSS 0.3%CVE-2026-82722HIGHAshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)EPSS 0.3%CVE-2026-82580MEDIUMAshAi echoes raw tool exception messages into the conversation, disclosing internal detailsEPSS 0.3%CVE-2026-82727LOWAshPhoenix Form.Auto leaks submitted params in an unknown _union_type error messageEPSS 0.3%CVE-2026-82725LOWAshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related dataEPSS 0.3%