Improper Neutralization of Special Elements in Ash-Project Ash_SQL
CVE-2026-78691

2.1LOW

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-78691?

The Ash_Project ash_sql library exhibits a vulnerability due to improper handling of special characters in user-supplied search terms. Attackers may exploit this flaw by injecting SQL LIKE wildcards, leading to unintended query behavior. The escape mechanisms in place are insufficient, as they fail to effectively neutralize backslashes already present in the input. This allows malicious users to manipulate search patterns, potentially widening matches, evading security checks, or causing query failures with malformed inputs. This vulnerability affects specific versions of ash_sql prior to 0.7.1, emphasizing the need for users to promptly update to secure their applications.

Affected Version(s)

ash_sql 0.1.1-rc.10 < 0.7.1

ash_sql cfc7da474c5be2190fd62664a83a689377a8d512

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.