ash-project ash_admin 中“使用随机性不足的值”漏洞 ash_admin 模块使用了一个硬编码的、公知内容安全策略(CSP)nonce(随机数),从而使得基于 nonce 的 CSP 保护机制失效。 当未指定 参数挂载路由时, 默认将 、 和 的 nonce 设为字面量常量 。随后, 会在每个响应中,将该固定值原样写入内联 和 标签的 属性中。该值是编译期常量,已在代码库中公开,且不会随请求动态更新。如果应用程序的 CSP 白名单中包含了这一已知的默认值,那么管理页面中任何 HTML 注入漏洞点
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_admin | 0.10.8 ~ 1.3.1 |
cpe:2.3:a:ash-project:ash_admin:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_admin | 99b8daed7b2f79d82fcd9e89338d41b0e1564aa7 ~ bc7a1cdf873b16971a8efec35d085f8bb706314f |
cpe:2.3:a:ash-project:ash_admin:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77956 | 10.0 CRITICAL | EEx template evaluation of prompt content in AshAi enables remote code execution |
| CVE-2026-77850 | 8.4 HIGH | Stored XSS in AshAdmin relationship typeahead via unescaped label_field content |
| CVE-2026-82673 | 8.3 HIGH | Path traversal in AshAdmin file uploads via unsanitized client filename |
| CVE-2026-82722 | 8.3 HIGH | AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node D |
| CVE-2026-75757 | 8.3 HIGH | AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a |
| CVE-2026-81315 | 7.4 HIGH | MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header |
| CVE-2026-75760 | 7.1 HIGH | AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a us |
| CVE-2026-82564 | 7.1 HIGH | Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unident |
| CVE-2026-82579 | 6.0 MEDIUM | AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of |
| CVE-2026-82580 | 5.3 MEDIUM | AshAi echoes raw tool exception messages into the conversation, disclosing internal detail |
| CVE-2026-81853 | 2.3 LOW | AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attrib |
| CVE-2026-82681 | 2.0 LOW | Query-parameter injection in AshAdmin row-action links via unencoded string primary keys |
No comments yet