Stored Cross-Site Scripting Vulnerability in AshAdmin by Ash Project
CVE-2026-77850
What is CVE-2026-77850?
A stored Cross-Site Scripting (XSS) vulnerability exists in the AshAdmin product that allows attacker-supplied content to be executed as a script in an administrator's browser. The vulnerability arises from how matched search terms are highlighted within dropdown components using Phoenix.HTML.raw/1, which disables output escaping. This allows potentially dangerous content, such as script injection via image tags, to execute when an admin selects a record. As a result, exploiting this flaw can grant attackers administrative privileges, allowing them to manipulate all exposed data in the AshAdmin dashboard. A patch has been made available that implements HTML-escaping to mitigate this risk.
Affected Version(s)
ash_admin 0.13.0 < 1.3.1
ash_admin eb940f4d7d857ca49368ae847f586d01c6f5ad35 < 07289191ccdac27dd70ab7c6413ed057bc7fdade
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
