All 7 CVE vulnerabilities found in ash_typescript, with AI-generated Chinese analysis, references, and POCs.
Vendor: ash-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-82731 | Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection CWE-601 | 2.3 | Low | 2026-09-01 |
| CVE-2026-74837 | Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter CWE-770 | 8.7 | High | 2026-09-01 |
| CVE-2026-82733 | Route handler return value echoed into AshTypescript error response CWE-209 | 6.3 | Medium | 2026-09-01 |
| CVE-2026-82732 | Declared argument constraints not enforced on AshTypescript typed controller routes CWE-20 | 6.3 | Medium | 2026-09-01 |
| CVE-2026-82730 | Authorization-redacted field values disclosed through AshTypescript result normalization CWE-863 | 8.2 | High | 2026-09-01 |
| CVE-2026-77950 | RPC error handler fails open in AshTypescript, disclosing unredacted errors CWE-209 | 6.3 | Medium | 2026-09-01 |
| CVE-2026-77856 | Unbounded atom creation from typed struct field names in AshTypescript field selector CWE-770 | 8.2 | High | 2026-09-01 |
All 7 known CVE vulnerabilities affecting ash_typescript with full Chinese analysis, references, and POCs where available.