PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75847 ash-project CVE debrief

The CVE-2026-75847 vulnerability, classified as Cleartext Storage of Sensitive Information, affects the ash_paper_trail library. This issue arises from AshPaperTrail.Resource.Transformers.CreateVersionResource deriving sensitivity from an ignore_attributes list that defaults to empty, leading to unintended exposure of sensitive attributes in public version resources. The vulnerability enables unauthorized access to sensitive information through the generated version resource's changes map, which is declared public. Affected versions range from 0.1.1 before 0.7.0. Developers and administrators using ash_paper_trail, especially those handling sensitive information, should be aware of this vulnerability and take steps to mitigate it. This includes verifying their inventory of ash_paper_trail installations, applying patches or upgrades, and reviewing security configurations to prevent unauthorized access to sensitive attributes stored in version resources.

Vendor
ash-project
Product
ash_paper_trail
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-30
Original CVE updated
2026-08-30
Advisory published
2026-08-30
Advisory updated
2026-08-30

Who should care

Developers and administrators using ash_paper_trail, especially those handling sensitive information, should be aware of this vulnerability and take steps to mitigate it. This includes verifying their inventory of ash_paper_trail installations, applying patches or upgrades, and reviewing security configurations to prevent unauthorized access to sensitive attributes stored in version resources. Security teams and vulnerability management teams should prioritize assessment and remediation efforts for this vulnerability due to its potential impact on data confidentiality and integrity within affected systems and environments where ash_paper_trail is deployed with sensitive attributes tracked in version resources. Operators of systems using ash_paper_trail should also be aware of potential operational impacts and take proactive measures to protect sensitive information from being exposed through this vulnerability in public version resources generated by AshPaperTrail. The vulnerability's impact on operators includes potential data breaches and the need for enhanced monitoring and security controls to mitigate risks associated with sensitive attribute exposure in ash_paper_trail version resources. Platform administrators and security teams should collaborate on implementing compensating controls and ensuring timely remediation of affected systems to minimize potential damage from exploitation of this vulnerability in ash_paper_trail installations handling sensitive information in version resources. Vulnerability management processes should include prioritization of CVE-2026-75847 based on the sensitivity of attributes tracked by ash_paper_trail in version resources and the potential for exploitation in the environment. Security configurations for ash_paper_trail should be reviewed to ensure that sensitive attributes are properly protected and that version resources are not inadvertently exposing sensitive information due to the default behavior of AshPaperTrail.Resource.Transformers.CreateVersionResource in deriving sensitivity from ignore_attributes lists that default to empty, leading to unintended exposure of sensitive attributes in public version resources. This

Technical summary

The ash_paper_trail library stores sensitive attributes in a public version resource, allowing an attacker with read access to recover the plaintext of these attributes. This issue arises from AshPaperTrail.Resource.Transformers.CreateVersionResource deriving sensitivity from an ignore_attributes list that defaults to empty, affecting versions from 0.1.1 before 0.7.0. The vulnerability enables unauthorized access to sensitive information through the generated version resource's changes map, which is declared public.

Defensive priority

Organizations using ash_paper_trail should verify their inventory and apply the patch or upgrade to version 0.7.0 or later to address the Cleartext Storage of Sensitive Information vulnerability.

Recommended defensive actions

  • Verify inventory of ash_paper_trail installations
  • Apply patch or upgrade to version 0.7.0 or later
  • Monitor for potential unauthorized access to sensitive attributes
  • Review and update security configurations for ash_paper_trail
  • Perform vulnerability assessment for ash_paper_trail deployments
  • Implement compensating controls for exposed systems
  • Track exceptions and retest remediated assets

Evidence notes

The CVE-2026-75847 issue affects ash_paper_trail versions from 0.1.1 before 0.7.0. AshPaperTrail stores sensitive attributes in a public version resource, making them recoverable by an attacker with read access. Evidence is based on official CVE and NVD records, as well as references from Erlef and GitHub. To verify, defenders should review the official CVE record and assess their inventory of ash_paper_trail installations for potential exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75847 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75847

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75847 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75847

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.erlef.org/cves/CVE-2026-75847.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ash-project/ash_paper_trail/commit/90efdb0769f83f7c5daba6a87758daebf4baf32c

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ash-project/ash_paper_trail/security/advisories/GHSA-wqjr-xmxp-j554

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://osv.dev/vulnerability/EEF-CVE-2026-75847

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.