Sensitive Information Exposure in ash_typescript by ash-project
CVE-2026-77950
What is CVE-2026-77950?
An issue exists in ash_typescript where improper error handling can lead to the generation of error messages containing sensitive internal data. This vulnerability allows unauthenticated attackers to exploit the application by provoking error scenarios that do not match the expected error shapes in the configured error handler. When such errors arise, the application fails to redact sensitive information, resulting in the exposure of potentially confidential data. Misconfigurations in error handling can inadvertently reveal internal states, making it essential for developers to implement robust error management processes and keep their applications up to date.
Affected Version(s)
ash_typescript 0.8.0 < 0.18.0
ash_typescript cb01cc8749e5a2a17fb45aedbe75df30a9f1126e < 59d8e985a98cf2e01794dbe5b919b897a95311f4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
