Browse all 86 CVE security advisories affecting ash-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.
The ash-project is a Python-based security tool for analyzing shell scripts to detect vulnerabilities and security issues. Historically, it has been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues, as evidenced by its six recorded CVEs. The tool's static analysis approach sometimes fails to properly sanitize input or handle complex shell constructs, leading to potential bypasses. While no major public security incidents have been documented, the consistent discovery of similar vulnerability classes suggests ongoing challenges in accurately parsing diverse shell script syntaxes and ensuring comprehensive security coverage.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-77454 | exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql — ash_sql CWE-863 | 5.9 | Medium | 2026-08-30 |
| CVE-2026-81316 | Same-named aggregates with differing filters are conflated in AshSql — ash_sql CWE-863 | 2.1 | Low | 2026-08-30 |
| CVE-2026-81318 | Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql — ash_sql CWE-863 | 2.1 | Low | 2026-08-30 |
| CVE-2026-78691 | Unescaped backslash allows LIKE wildcard injection in AshSql string search — ash_sql CWE-943 | 2.1 | Low | 2026-08-30 |
| CVE-2026-80227 | SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql — ash_sql CWE-697 | 2.1 | Low | 2026-08-30 |
This page lists every published CVE security advisory associated with ash-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.