Cleartext Storage Vulnerability in Ash-Paper-Trail by Ash-Project
CVE-2026-77970
5.9MEDIUM
What is CVE-2026-77970?
The Ash-Paper-Trail component of the Ash-Project contains a vulnerability that allows attackers with read access to the generated version resource to retrieve sensitive nested values from embedded resources, unions, or lists in cleartext. Despite safeguards like sensitive_attributes :redact and :ignore, which apply only to the top-level attributes, the vulnerability allows non-sensitive attributes containing sensitive fields (e.g., tokens from accepted credentials) to be stored in version tables without encryption, exposing critical data.
Affected Version(s)
ash_paper_trail 0.3.0 < 0.7.0
ash_paper_trail ffe5e03b14d26b73bff17f3eca811591788aba9c < 0cd4acfe7f48397673d8594fb5e2cd0f1bda6e40
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
