Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77970— Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions

Quick assessment

Affected
ash-project ash_paper_trail
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: 敏感信息明文存储漏洞 中存在一个敏感信息明文存储漏洞,使得拥有生成版本资源读权限的攻击者能够恢复嵌入资源、联合类型或列表内部嵌套的敏感值。 和 选项仅作用于被跟踪资源的顶层属性。 以及 中存储操作输入的路径,其敏感属性集合仅从资源自身的属性中推导,而不会深入嵌入资源、联合类型或列表中的值。因此,包含带有 字段的嵌入资源(例如,包含令牌的身份验证凭据嵌入)的非敏感属性或操作参数,会以明文形式写入版本表中。 影响版本: 从 0.3.0 到 0.7.0 之前的版本。

CVSS 5.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77970

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
Source: CVE Program / CVE List V5
Vulnerability Description
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore only act on the tracked resource's top-level attributes. maybe_redact_changes/3 and the stored-action-input path in AshPaperTrail.Resource.Changes.CreateNewVersion derive the sensitive set from the resource's own attributes and never descend into embedded, union, or list values, so a non-sensitive attribute or action argument that holds an embed with a sensitive? field (for example an accepted credentials embed carrying a token) is written to the version table in cleartext. This issue affects ash_paper_trail: from 0.3.0 before 0.7.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的明文存储
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ash-project ash_paper_trail 0.3.0 ~ 0.7.0 cpe:2.3:a:ash-project:ash_paper_trail:*:*:*:*:*:*:*:*
ash-project ash_paper_trail ffe5e03b14d26b73bff17f3eca811591788aba9c ~ 0cd4acfe7f48397673d8594fb5e2cd0f1bda6e40 cpe:2.3:a:ash-project:ash_paper_trail:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-77970

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77970

登录查看更多情报信息。

Patches & Fixes for CVE-2026-77970 (1)

Vendor Advisories for CVE-2026-77970 (3)

Same Patch Batch · ash-project · 2026-08-30 · 4 CVEs total

CVE-2026-75847 5.9 MEDIUM Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
CVE-2026-77846 2.1 LOW JSON path injection via unescaped get_path segments in AshSqlite
CVE-2026-77831 2.1 LOW Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking

IV. Related Vulnerabilities

V. Comments for CVE-2026-77970

No comments yet


Leave a comment