以下是该漏洞描述的中文翻译: ash_phoenix 中存在“授权不当”(Incorrect Authorization)漏洞,其 SubdomainHook 授权回调在租户(tenant)为 nil 的情况下被调用,导致基于租户范围的访问控制检查无法看到本应强制执行的租户信息。 详细技术说明: 在 中挂载了一个 钩子来分配租户(assign tenant),并在同一个 中立即调用了 。然而,租户的赋值操作只有在 LiveView 稍后执行 时才会真正写入,而这发生在 返回之后。因此, 读取到一个未设置的 assi
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_phoenix | 2.1.26 ~ 2.3.25 |
cpe:2.3:a:ash-project:ash_phoenix:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_phoenix | 9a5ea4d377bc263de321d79574872a3dfc4fb541 ~ b396e1aa5c6bdec39255f19cf938b539e6d28b71 |
cpe:2.3:a:ash-project:ash_phoenix:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77956 | 10.0 CRITICAL | EEx template evaluation of prompt content in AshAi enables remote code execution |
| CVE-2026-77850 | 8.4 HIGH | Stored XSS in AshAdmin relationship typeahead via unescaped label_field content |
| CVE-2026-82673 | 8.3 HIGH | Path traversal in AshAdmin file uploads via unsanitized client filename |
| CVE-2026-82722 | 8.3 HIGH | AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node D |
| CVE-2026-75757 | 8.3 HIGH | AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a |
| CVE-2026-81315 | 7.4 HIGH | MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header |
| CVE-2026-75760 | 7.1 HIGH | AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a us |
| CVE-2026-82564 | 7.1 HIGH | Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unident |
| CVE-2026-82726 | 6.3 MEDIUM | AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary t |
| CVE-2026-82579 | 6.0 MEDIUM | AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of |
| CVE-2026-82580 | 5.3 MEDIUM | AshAi echoes raw tool exception messages into the conversation, disclosing internal detail |
| CVE-2026-82725 | 2.3 LOW | AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private |
| CVE-2026-82727 | 2.3 LOW | AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message |
| CVE-2026-81853 | 2.3 LOW | AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attrib |
| CVE-2026-81852 | 2.1 LOW | AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass |
| CVE-2026-82681 | 2.0 LOW | Query-parameter injection in AshAdmin row-action links via unencoded string primary keys |
No comments yet