以下是该漏洞描述信息的中文翻译: 漏洞描述: ash-project 的 ash_admin 中存在一个存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。攻击者提供的记录内容会以脚本的形式在管理员的浏览器中执行。 详细说明: 和 这两个关系型自动补全(typeahead)组件会将匹配的搜索词用 标签进行高亮,并调用 渲染整个字符串。被高亮的值是目标记录的 字段,而该字段通常是普通数据库内容,往往由权限较低的用户写入。由于 会对整个字符串禁用输出转义,类似 这样的存储型 labe
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_admin | 0.13.0 ~ 1.3.1 |
cpe:2.3:a:ash-project:ash_admin:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_admin | eb940f4d7d857ca49368ae847f586d01c6f5ad35 ~ 07289191ccdac27dd70ab7c6413ed057bc7fdade |
cpe:2.3:a:ash-project:ash_admin:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77956 | 10.0 CRITICAL | EEx template evaluation of prompt content in AshAi enables remote code execution |
| CVE-2026-82673 | 8.3 HIGH | Path traversal in AshAdmin file uploads via unsanitized client filename |
| CVE-2026-82722 | 8.3 HIGH | AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node D |
| CVE-2026-75757 | 8.3 HIGH | AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a |
| CVE-2026-81315 | 7.4 HIGH | MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header |
| CVE-2026-75760 | 7.1 HIGH | AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a us |
| CVE-2026-82564 | 7.1 HIGH | Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unident |
| CVE-2026-82579 | 6.0 MEDIUM | AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of |
| CVE-2026-82580 | 5.3 MEDIUM | AshAi echoes raw tool exception messages into the conversation, disclosing internal detail |
| CVE-2026-81853 | 2.3 LOW | AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attrib |
| CVE-2026-81852 | 2.1 LOW | AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass |
| CVE-2026-82681 | 2.0 LOW | Query-parameter injection in AshAdmin row-action links via unencoded string primary keys |
No comments yet