ash_admin 中通过用户可控密钥绕过授权的漏洞 Ash-project 的 ash_admin 将记录查询 URL 变成了针对敏感属性的“相等性预言机”(equality oracle)。 具体来说, 函数会对组合主键格式(Base64 加 ETF)进行解码,并原样将解码后的映射(map)作为查询过滤器返回,而没有验证其中的键是否为该资源的主键字段。反序列化守卫机制虽然限制了数据大小、禁止新增 atom 和 fun,并拒绝嵌套表达式,且 模式仍允许任意已内省(interned)的属性名,但没有任何机制限制返回
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_admin | 0.1.0 ~ 1.3.1 |
cpe:2.3:a:ash-project:ash_admin:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_admin | 98b03baa8422b94dd13e305bf08b8ee3f7232c7b ~ 3c3e905d47f1155dcc1ca3fb347348b05a66065a |
cpe:2.3:a:ash-project:ash_admin:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77956 | 10.0 CRITICAL | EEx template evaluation of prompt content in AshAi enables remote code execution |
| CVE-2026-77850 | 8.4 HIGH | Stored XSS in AshAdmin relationship typeahead via unescaped label_field content |
| CVE-2026-82673 | 8.3 HIGH | Path traversal in AshAdmin file uploads via unsanitized client filename |
| CVE-2026-82722 | 8.3 HIGH | AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node D |
| CVE-2026-75757 | 8.3 HIGH | AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a |
| CVE-2026-81315 | 7.4 HIGH | MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header |
| CVE-2026-75760 | 7.1 HIGH | AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a us |
| CVE-2026-82564 | 7.1 HIGH | Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unident |
| CVE-2026-82579 | 6.0 MEDIUM | AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of |
| CVE-2026-82580 | 5.3 MEDIUM | AshAi echoes raw tool exception messages into the conversation, disclosing internal detail |
| CVE-2026-81852 | 2.1 LOW | AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass |
| CVE-2026-82681 | 2.0 LOW | Query-parameter injection in AshAdmin row-action links via unencoded string primary keys |
No comments yet