Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ash-project — Vulnerabilities & Security Advisories 86

Browse all 86 CVE security advisories affecting ash-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The ash-project is a Python-based security tool for analyzing shell scripts to detect vulnerabilities and security issues. Historically, it has been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues, as evidenced by its six recorded CVEs. The tool's static analysis approach sometimes fails to properly sanitize input or handle complex shell constructs, leading to potential bypasses. While no major public security incidents have been documented, the consistent discovery of similar vulnerability classes suggests ongoing challenges in accurately parsing diverse shell script syntaxes and ensuring comprehensive security coverage.

CVE ID Title CVSS Severity Published
CVE-2026-101028 Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts — ash CWE-863 6.0 Medium 2026-10-09
CVE-2026-94201 Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash — ash CWE-770 8.2 High 2026-10-05
CVE-2026-93477 Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash — ash CWE-915 5.9 Medium 2026-09-25
CVE-2026-86338 Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle — ash CWE-1220 6.0 Medium 2026-09-16
CVE-2026-78216 AshLua eval read operations can read field-policy-protected fields via aggregates — ash_lua CWE-1220 6.0 Medium 2026-09-08
CVE-2026-78230 AshAi aggregate tool can read field-policy-protected fields — ash_ai CWE-1220 6.0 Medium 2026-09-08
CVE-2026-82710 Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata — usage_rules CWE-150 2.3 Low 2026-09-08
CVE-2026-82584 Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata — igniter CWE-150 2.3 Low 2026-09-07
CVE-2026-82586 AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes — ash_lua CWE-424 8.2 High 2026-09-07
CVE-2026-81638 Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry — ash_double_entry CWE-173 2.1 Low 2026-09-07
CVE-2026-82758 ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint — ash_authentication_oauth2_server CWE-287 6.3 Medium 2026-09-07
CVE-2026-82757 ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF — ash_authentication_oauth2_server CWE-918 6.3 Medium 2026-09-07
CVE-2026-82756 ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection — ash_authentication_oauth2_server CWE-116 6.3 Medium 2026-09-07
CVE-2026-82755 ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion — ash_authentication_oauth2_server CWE-524 6.3 Medium 2026-09-07
CVE-2026-82754 ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls — ash_authentication_oauth2_server CWE-424 6.3 Medium 2026-09-07
CVE-2026-82753 Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server — ash_authentication_oauth2_server CWE-770 8.2 High 2026-09-07
CVE-2026-82752 Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length — ash CWE-1284 5.9 Medium 2026-09-05
CVE-2026-82747 Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor — ash CWE-863 5.9 Medium 2026-09-01
CVE-2026-82749 Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records — ash CWE-863 5.9 Medium 2026-09-01
CVE-2026-82748 Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another — ash CWE-863 2.1 Low 2026-09-01
CVE-2026-82746 Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records — ash CWE-862 5.9 Medium 2026-09-01
CVE-2026-82745 ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness — ash CWE-284 5.9 Medium 2026-09-01
CVE-2026-82744 Ash.Reactor change step fails open, skipping a change when its where guard raises — ash CWE-636 2.1 Low 2026-09-01
CVE-2026-82743 Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads — ash CWE-400 2.1 Low 2026-09-01
CVE-2026-82742 Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory — ash CWE-400 5.9 Medium 2026-09-01
CVE-2026-82741 Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion — ash CWE-1287 2.1 Low 2026-09-01
CVE-2026-82740 Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs — ash CWE-20 2.1 Low 2026-09-01
CVE-2026-82739 Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error — ash CWE-209 2.1 Low 2026-09-01
CVE-2026-82738 Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service — ash CWE-20 5.9 Medium 2026-09-01
CVE-2026-82737 Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads — ash CWE-190 5.9 Medium 2026-09-01

This page lists every published CVE security advisory associated with ash-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.