Sensitive Information Exposure in ash_typescript by ash-project
CVE-2026-77950

6.3MEDIUM

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-77950?

An issue exists in ash_typescript where improper error handling can lead to the generation of error messages containing sensitive internal data. This vulnerability allows unauthenticated attackers to exploit the application by provoking error scenarios that do not match the expected error shapes in the configured error handler. When such errors arise, the application fails to redact sensitive information, resulting in the exposure of potentially confidential data. Misconfigurations in error handling can inadvertently reveal internal states, making it essential for developers to implement robust error management processes and keep their applications up to date.

Affected Version(s)

ash_typescript 0.8.0 < 0.18.0

ash_typescript cb01cc8749e5a2a17fb45aedbe75df30a9f1126e < 59d8e985a98cf2e01794dbe5b919b897a95311f4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Torkild Gundersen Kjevik / Ash Project
Jonatan Männchen / EEF
.