Improper Attribute Modification in Ash-Project's Ash_Oban Plugin
CVE-2026-78038
What is CVE-2026-78038?
The Ash_Oban plugin is susceptible to improper handling of user input due to a flaw in how dynamically determined attributes are managed. An attacker can exploit this vulnerability by manipulating the :args option in the AshOban.build_trigger/3 function, allowing them to redirect update or destruction actions to different records, compromising tenant isolation. This flaw arises because the merging of user inputs does not appropriately handle key collisions due to JSON processing, leading to unexpected behavior and potential authorization bypass, especially in applications that inadequately shield this option from direct user influence. Users utilizing versions from 0.2.5 up to 0.8.14 are recommended to apply the fixes provided in recent patches to safeguard their applications.
Affected Version(s)
ash_oban 0.2.5 < 0.8.14
ash_oban ce079229ecdf0d323da2b554f30fc569e54660f0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
