Stored Cross-Site Scripting Vulnerability in AshAdmin by Ash Project
CVE-2026-77850

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-77850?

A stored Cross-Site Scripting (XSS) vulnerability exists in the AshAdmin product that allows attacker-supplied content to be executed as a script in an administrator's browser. The vulnerability arises from how matched search terms are highlighted within dropdown components using Phoenix.HTML.raw/1, which disables output escaping. This allows potentially dangerous content, such as script injection via image tags, to execute when an admin selects a record. As a result, exploiting this flaw can grant attackers administrative privileges, allowing them to manipulate all exposed data in the AshAdmin dashboard. A patch has been made available that implements HTML-escaping to mitigate this risk.

Affected Version(s)

ash_admin 0.13.0 < 1.3.1

ash_admin eb940f4d7d857ca49368ae847f586d01c6f5ad35 < 07289191ccdac27dd70ab7c6413ed057bc7fdade

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.