Cleartext Storage Vulnerability in Ash-Paper-Trail by Ash-Project
CVE-2026-77970

5.9MEDIUM

Key Information:

Vendor
CVE Published:
30 August 2026

What is CVE-2026-77970?

The Ash-Paper-Trail component of the Ash-Project contains a vulnerability that allows attackers with read access to the generated version resource to retrieve sensitive nested values from embedded resources, unions, or lists in cleartext. Despite safeguards like sensitive_attributes :redact and :ignore, which apply only to the top-level attributes, the vulnerability allows non-sensitive attributes containing sensitive fields (e.g., tokens from accepted credentials) to be stored in version tables without encryption, exposing critical data.

Affected Version(s)

ash_paper_trail 0.3.0 < 0.7.0

ash_paper_trail ffe5e03b14d26b73bff17f3eca811591788aba9c < 0cd4acfe7f48397673d8594fb5e2cd0f1bda6e40

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.