Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ash-project — Vulnerabilities & Security Advisories 86

Browse all 86 CVE security advisories affecting ash-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The ash-project is a Python-based security tool for analyzing shell scripts to detect vulnerabilities and security issues. Historically, it has been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues, as evidenced by its six recorded CVEs. The tool's static analysis approach sometimes fails to properly sanitize input or handle complex shell constructs, leading to potential bypasses. While no major public security incidents have been documented, the consistent discovery of similar vulnerability classes suggests ongoing challenges in accurately parsing diverse shell script syntaxes and ensuring comprehensive security coverage.

CVE ID Title CVSS Severity Published
CVE-2026-82736 Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass — ash CWE-180 2.1 Low 2026-09-01
CVE-2026-82735 Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service — ash CWE-400 5.9 Medium 2026-09-01
CVE-2026-82734 Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal — ash CWE-1284 2.1 Low 2026-09-01
CVE-2026-82731 Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection — ash_typescript CWE-601 2.3 Low 2026-09-01
CVE-2026-74837 Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter — ash_typescript CWE-770 8.7 High 2026-09-01
CVE-2026-82733 Route handler return value echoed into AshTypescript error response — ash_typescript CWE-209 6.3 Medium 2026-09-01
CVE-2026-82732 Declared argument constraints not enforced on AshTypescript typed controller routes — ash_typescript CWE-20 6.3 Medium 2026-09-01
CVE-2026-82730 Authorization-redacted field values disclosed through AshTypescript result normalization — ash_typescript CWE-863 8.2 High 2026-09-01
CVE-2026-77950 RPC error handler fails open in AshTypescript, disclosing unredacted errors — ash_typescript CWE-209 6.3 Medium 2026-09-01
CVE-2026-77856 Unbounded atom creation from typed struct field names in AshTypescript field selector — ash_typescript CWE-770 8.2 High 2026-09-01
CVE-2026-82725 AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data — ash_phoenix CWE-639 2.3 Low 2026-08-31
CVE-2026-82724 Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain — ash_phoenix CWE-863 7.6 High 2026-08-31
CVE-2026-82726 AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant — ash_phoenix CWE-625 6.3 Medium 2026-08-31
CVE-2026-82727 AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message — ash_phoenix CWE-209 2.3 Low 2026-08-31
CVE-2026-82673 Path traversal in AshAdmin file uploads via unsanitized client filename — ash_admin CWE-22 8.3 High 2026-08-31
CVE-2026-81853 AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle — ash_admin CWE-639 2.3 Low 2026-08-31
CVE-2026-81852 AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass — ash_admin CWE-330 2.1 Low 2026-08-31
CVE-2026-82681 Query-parameter injection in AshAdmin row-action links via unencoded string primary keys — ash_admin CWE-116 2.0 Low 2026-08-31
CVE-2026-77850 Stored XSS in AshAdmin relationship typeahead via unescaped label_field content — ash_admin CWE-79 8.4 High 2026-08-31
CVE-2026-82722 AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS) — ash_admin CWE-770 8.3 High 2026-08-31
CVE-2026-75757 AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain — ash_admin CWE-565 8.3 High 2026-08-31
CVE-2026-75760 AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error — ash_ai CWE-209 7.1 High 2026-08-31
CVE-2026-82580 AshAi echoes raw tool exception messages into the conversation, disclosing internal details — ash_ai CWE-209 5.3 Medium 2026-08-31
CVE-2026-82579 AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service — ash_ai CWE-835 6.0 Medium 2026-08-31
CVE-2026-82564 Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records — ash_ai CWE-639 7.1 High 2026-08-31
CVE-2026-81315 MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header — ash_ai CWE-346 7.4 High 2026-08-31
CVE-2026-77956 EEx template evaluation of prompt content in AshAi enables remote code execution — ash_ai CWE-94 8.9 High 2026-08-31
CVE-2026-78693 Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names — ash_graphql CWE-209 6.9 Medium 2026-08-30
CVE-2026-80223 Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read — ash_graphql CWE-863 7.1 High 2026-08-30
CVE-2026-81636 Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of service — ash_graphql CWE-770 8.7 High 2026-08-30

This page lists every published CVE security advisory associated with ash-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.