PatchSiren

ash-project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ash-project CVE published 2026-09-25

CVE-2026-93477

CVE-2026-93477 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. The vulnerability arises from the library's handling of private action arguments in bulk operations, which could lead to integrity violations or privilege escalation. Defenders a [truncated]

LOW ash-project CVE published 2026-09-08

CVE-2026-82710

CVE-2026-82710 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. The vulnerability affects usage_rules from 0.1.18 before 1.2.8. A malicious package can embed ANSI terminal escape sequences in its indexed documentation, potentially l [truncated]

MEDIUM ash-project CVE published 2026-09-07

CVE-2026-82758

CVE-2026-82758 Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. The vulnerability exists due to improper handling of secrets in the resolve_secret/3 function of AshAuthentication.Oauth2Server, which treats any return other than {:ok, _ [truncated]

MEDIUM ash-project CVE published 2026-09-07

CVE-2026-82757

A Server-Side Request Forgery (SSRF) vulnerability exists in ash_authentication_oauth2_server, allowing an attacker to control a client metadata URL and its DNS to make the server connect to internal or loopback addresses due to a flawed outbound policy for CIMD metadata fetches. This issue affects ash_authentication_oauth2_server versions from 0.3.0 before 0.3.1. Defenders should assess exposure, verify [truncated]

MEDIUM ash-project CVE published 2026-09-07

CVE-2026-82756

CVE-2026-82756 Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. The vulnerability affects multi-tenant applications using request-controlled data. Defenders should assess configurations and verify versions to prevent potential aut [truncated]

MEDIUM ash-project CVE published 2026-09-07

CVE-2026-82755

CVE-2026-82755 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T23:16:52.580Z and has not been modified since then. This medium-severity vulnerability in ash_authentication_oauth2_server can lead to sensitive information disclosure across tenants due to improper cache handling. Affected deployments using shared HTTP caches should assess exposure and verify remediatio [truncated]

MEDIUM ash-project CVE published 2026-09-07

CVE-2026-82754

CVE-2026-82754 Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server allows OAuth endpoints to be exposed under an unintended URL prefix. The vulnerability arises from oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwarding the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. This exposure may bypas [truncated]

HIGH ash-project CVE published 2026-09-07

CVE-2026-82753

CVE-2026-82753 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T23:16:52.227Z and has not been modified since then. The vulnerability allows an unauthenticated attacker to exhaust database storage and memory by creating permanent client rows with multi-megabyte strings through the /authorize endpoint. This issue affects ash_authentication_oauth2_server: from 0.3.0 be [truncated]

HIGH ash-project CVE published 2026-09-07

CVE-2026-82586

CVE-2026-82586 Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows unauthorized attribute access. Affected versions require verification. Vendor patch status is unknown. The vulnerability impacts data confidentiality, allowing unauthorized access to attributes not on the exposed-field allow-list. Defenders should verify exposure, assess Lua script handling, and update vulnera [truncated]

LOW ash-project CVE published 2026-09-07

CVE-2026-82584

A vulnerability in the ash-project igniter package allows a malicious package publisher to forge the mix igniter.install confirmation prompt by embedding ANSI terminal escape sequences in package metadata. This issue affects igniter versions from 0.8.1 before 0.8.4. The vulnerability can be exploited by embedding ANSI terminal escape sequences in package metadata, allowing a malicious package publisher to [truncated]

LOW ash-project CVE published 2026-09-07

CVE-2026-81638

PatchSiren debrief for CVE-2026-81638: Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. This vulnerability affects ash_double_entry versions from 0.1.0 before 1.0.19. The issue arises from the library's improper handling of alternate encodings of identifiers, which can lead to desync [truncated]

LOW ash-project CVE published 2026-08-31

CVE-2026-82727

The CVE-2026-82727 vulnerability is a Generation of Error Message Containing Sensitive Information issue in ash_phoenix. An attacker can exploit this vulnerability to leak sensitive information, including secrets submitted alongside a union form field, into logs, crash reports, and the dev error page. This occurs when AshPhoenix.Form.Auto builds a union sub-form and the submitted _union_type does not matc [truncated]

LOW ash-project CVE published 2026-08-31

CVE-2026-82725

An AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T04:17:29.167Z and has not been modified since then. This vulnerability affects ash_phoenix, specifically versions from 0.6.0-rc.1 before 2.3.25, and involves an Authorization Bypass Through User-Controlled Key vulnerability. Users of ash_phoenix should verify their versions and apply patches. [truncated]

HIGH ash-project CVE published 2026-08-31

CVE-2026-82724

The CVE-2026-82724 vulnerability is an Incorrect Authorization issue in ash-project ash_phoenix. This occurs because the SubdomainHook authorization callback is invoked with a nil tenant, causing tenant-scoped access checks to fail. The issue arises from delayed tenant assignment until LiveView runs handle_params, allowing handle_subdomain to execute with an unset tenant. The fix involves running handle_s [truncated]

HIGH ash-project CVE published 2026-08-31

CVE-2026-82722

PatchSiren debrief for CVE-2026-82722 based on the supplied source corpus. The CVE record was published on 2026-08-31T03:16:43.817Z and has not been modified since then. This vulnerability affects ash_admin, particularly versions from 0.1.0 before 1.3.1, allowing for denial of service due to Allocation of Resources Without Limits or Throttling. Users should be aware of the potential for the entire node to [truncated]

LOW ash-project CVE published 2026-08-31

CVE-2026-82681

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T03:16:43.643Z and has not been modified since then. This Improper Encoding or Escaping of Output vulnerability in ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links. The Table, DataTable, and Show components built row-action URL [truncated]

HIGH ash-project CVE published 2026-08-31

CVE-2026-82673

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T03:16:43.473Z and has not been modified since then. The vulnerability exists in ash_admin, affecting versions from 0.13.7 before 1.3.1. The issue arises from improper limitation of a pathname to a restricted directory, allowing path traversal attacks. This could allow attackers to write arbitrary [truncated]

LOW ash-project CVE published 2026-08-31

CVE-2026-81853

The CVE-2026-81853 vulnerability is an Authorization Bypass Through User-Controlled Key issue in ash_admin. This vulnerability allows an attacker to bypass authorization by manipulating the primary key used in record-lookup URLs. The issue arises from AshAdmin.Helpers.decode_primary_key/2, which decodes composite-primary-key form (Base64 plus ETF) and returns the decoded map as the lookup filter without v [truncated]

LOW ash-project CVE published 2026-08-31

CVE-2026-81852

The CVE-2026-81852 vulnerability is a Use of Insufficiently Random Values issue in the ash-project ash_admin module. A hardcoded, publicly known CSP nonce is used, defeating nonce-based Content-Security-Policy protection. This affects ash_admin versions from 0.10.8 before 1.3.1. The fix generates a fresh random nonce per request. To address this, developers should review and apply patches, update ash_admi [truncated]

HIGH ash-project CVE published 2026-08-31

CVE-2026-77850

The CVE-2026-77850 vulnerability is a stored Cross-site Scripting (XSS) issue in ash_admin, which executes attacker-supplied record content as script in an administrator's browser. The vulnerability affects ash_admin versions from 0.13.0 before 1.3.1. This issue has a high CVSS score of 8.4 and is considered HIGH severity. The relationship typeahead components AshAdmin.Components.Resource.RelationshipFiel [truncated]

HIGH ash-project CVE published 2026-08-31

CVE-2026-75757

The CVE-2026-75757 vulnerability is a Reliance on Cookies without Validation and Integrity Checking issue in ash_admin. This vulnerability allows an attacker controlling a sibling subdomain to rebind an admin's session by setting shadowing cookies that flow unvalidated into the admin's LiveSocket connect params. The vulnerability affects ash_admin versions from 0.9.1 before 1.3.1. Organizations using ash_ [truncated]

MEDIUM ash-project CVE published 2026-08-31

CVE-2026-82580

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T02:17:02.440Z and has not been modified since then. This vulnerability affects ash_ai versions from 0.6.0 to before 1.0.0, where exceptions raised during tool execution were serialized verbatim and sent to chat users without filtering, potentially disclosing internal error text.

MEDIUM ash-project CVE published 2026-08-31

CVE-2026-82579

The CVE-2026-82579 vulnerability is caused by a Loop with Unreachable Exit Condition (Infinite Loop) in the ash-project ash_ai tool. An attacker who can influence a model's output can hang the tool loop and drive unbounded, repeated model requests. This issue affects ash_ai versions from 0.6.0 before 1.0.0. The vulnerability has a CVSS score of 6, indicating a medium severity level. Users of affected vers [truncated]

HIGH ash-project CVE published 2026-08-31

CVE-2026-82564

The CVE-2026-82564 vulnerability is an Authorization Bypass Through User-Controlled Key issue in ash_ai. It allows a caller of an identity-configured tool to update or destroy records it never identified. The vulnerability affects ash_ai versions from 0.6.0 to before 1.0.0. The issue arises from the improper construction of update and destroy filters in the AshAi.Tool.Execution module. The fix involves va [truncated]

HIGH ash-project CVE published 2026-08-31

CVE-2026-75760

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T02:17:01.313Z and has not been modified since then. The ash_ai product is vulnerable to Generation of Error Message Containing Sensitive Information. When the embedding provider call fails, the error message could potentially disclose sensitive information such as the request URL, provider respon [truncated]

HIGH ash-project CVE published 2026-08-31

CVE-2026-81315

Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. The vulnerability exists in ash_ai versions from 0.8.0 before 1.0.0 due to a default allowed_origins setting of nil. This allows an attacker to bypass DNS-rebinding protection by sendin [truncated]

CRITICAL ash-project CVE published 2026-08-31

CVE-2026-77956

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T01:16:49.563Z and has not been modified since then. This critical vulnerability affects ash_ai versions from 0.1.0 before 1.0.0, allowing remote, unauthenticated clients to execute arbitrary Elixir code due to improper control of code generation. Users of affected versions should be aware of this [truncated]

LOW ash-project CVE published 2026-08-30

CVE-2026-82367

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T19:17:29.877Z and has not been modified since then. The vulnerability affects ash_graphql library versions from 1.4.0 before 1.11.0, allowing exposure of data elements to wrong sessions. Users of ash_graphql library, especially those handling sensitive data, should review vendor documentation and [truncated]

HIGH ash-project CVE published 2026-08-30

CVE-2026-81636

The CVE-2026-81636 vulnerability in ash_graphql allows an unauthenticated client to bypass the GraphQL query-complexity limit, potentially leading to an unbounded database read. This issue affects ash_graphql versions from 0.16.23 before 1.11.0. The fix adds first and last clauses clamped to the action's page size. Organizations using ash_graphql should prioritize patching and monitoring to prevent potent [truncated]

MEDIUM ash-project CVE published 2026-08-30

CVE-2026-81633

The CVE-2026-81633 record describes an Improper Input Validation vulnerability in ash_graphql, a library used for GraphQL queries. This vulnerability allows unauthenticated clients to crash relay nodes with an unhandled KeyError, potentially exposing stack traces. The issue affects ash_graphql versions from 0.27.0 before 1.11.0. Users of affected versions should verify and apply vendor remediation, implem [truncated]