Cleartext Storage Vulnerability in ash_paper_trail by Ash Project
CVE-2026-75847

5.9MEDIUM

Key Information:

Vendor
CVE Published:
30 August 2026

What is CVE-2026-75847?

The ash_paper_trail component of the Ash Project contains a cleartext storage vulnerability, allowing attackers with read access to exposed version resources to potentially recover sensitive information. The vulnerability arises from the improper handling of tracked sensitive attributes, which are incorrectly stored in the changes map and designated as non-sensitive. This oversight permits the disclosure of sensitive values during default read actions, log outputs, and error messages, removing essential redaction and increasing the risk of data exposure. This flaw impacts versions of ash_paper_trail from 0.1.1 to just before 0.7.0.

Affected Version(s)

ash_paper_trail 0.1.1 < 0.7.0

ash_paper_trail e379ca90a0c4db54d07a9d1556fd12f2413f6e98 < 90efdb0769f83f7c5daba6a87758daebf4baf32c

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zach Daniel / Ash Project
Peter Ullrich
Peter Ullrich
Jonatan Männchen / EEF
.