Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ash-project — Vulnerabilities & Security Advisories 86

Browse all 86 CVE security advisories affecting ash-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The ash-project is a Python-based security tool for analyzing shell scripts to detect vulnerabilities and security issues. Historically, it has been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues, as evidenced by its six recorded CVEs. The tool's static analysis approach sometimes fails to properly sanitize input or handle complex shell constructs, leading to potential bypasses. While no major public security incidents have been documented, the consistent discovery of similar vulnerability classes suggests ongoing challenges in accurately parsing diverse shell script syntaxes and ensuring comprehensive security coverage.

CVE ID Title CVSS Severity Published
CVE-2026-81633 Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment — ash_graphql CWE-20 6.9 Medium 2026-08-30
CVE-2026-81643 Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first notification — ash_graphql CWE-863 2.3 Low 2026-08-30
CVE-2026-82367 Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic — ash_graphql CWE-488 2.3 Low 2026-08-30
CVE-2026-81322 Cloaked plaintext leaks through a non-sensitive action argument in AshCloak — ash_cloak CWE-200 2.1 Low 2026-08-30
CVE-2026-81319 Unsafe deserialization of decrypted terms enables node DoS in AshCloak — ash_cloak CWE-502 5.9 Medium 2026-08-30
CVE-2026-78699 rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres — ash_postgres CWE-252 7.2 High 2026-08-30
CVE-2026-77454 exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql — ash_sql CWE-863 5.9 Medium 2026-08-30
CVE-2026-81316 Same-named aggregates with differing filters are conflated in AshSql — ash_sql CWE-863 2.1 Low 2026-08-30
CVE-2026-81318 Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql — ash_sql CWE-863 2.1 Low 2026-08-30
CVE-2026-78691 Unescaped backslash allows LIKE wildcard injection in AshSql string search — ash_sql CWE-943 2.1 Low 2026-08-30
CVE-2026-80227 SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql — ash_sql CWE-697 2.1 Low 2026-08-30
CVE-2026-78228 Unbounded handle_error recursion enables denial of service in AshOban triggers — ash_oban CWE-674 5.9 Medium 2026-08-30
CVE-2026-78038 Job argument injection via :args overrides primary_key and tenant in AshOban — ash_oban CWE-915 5.9 Medium 2026-08-30
CVE-2026-77846 JSON path injection via unescaped get_path segments in AshSqlite — ash_sqlite CWE-943 2.1 Low 2026-08-30
CVE-2026-77831 Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking — ash_paper_trail CWE-407 2.1 Low 2026-08-30
CVE-2026-77970 Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions — ash_paper_trail CWE-312 5.9 Medium 2026-08-30
CVE-2026-75847 Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail — ash_paper_trail CWE-312 5.9 Medium 2026-08-30
CVE-2026-67579 Filter expression injection via forged keyset pagination cursor in Ash — ash CWE-502 7.5 High 2026-08-12
CVE-2026-70395 Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash — ash CWE-943 2.1 Low 2026-08-09
CVE-2026-69659 Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset — ash CWE-502 5.9 Medium 2026-08-09
CVE-2026-55736 Private action arguments can be set by user input in Ash — ash CWE-915 - - 2026-06-23
CVE-2026-34593 Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash — ash CWE-400 6.5AI Medium AI 2026-04-02
CVE-2025-48044 Authorization bypass when bypass policy condition evaluates to true — ash CWE-863 8.6 High 2025-10-17
CVE-2025-48043 Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization — ash CWE-863 8.6 High 2025-10-10
CVE-2025-48042 Before action hooks may execute in certain scenarios despite a request being forbidden — ash CWE-863 7.1 High 2025-09-07
CVE-2024-49756 AshPostgres empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability. — ash_postgres CWE-552 5.3 Medium 2024-10-23

This page lists every published CVE security advisory associated with ash-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.