Insufficient Random Value Vulnerability in Ash-Project's Ash_Admin
CVE-2026-81852
What is CVE-2026-81852?
An insufficiently random values vulnerability exists in Ash-Project's Ash_Admin, where a hardcoded, publicly known Content Security Policy (CSP) nonce compromises nonce-based protections. The application defaults to a constant nonce value for inline scripts and styles, allowing attackers to exploit any HTML-injection sink on admin pages. This issue severely undermines the intended security measures, as the nonces are predictable and reused across requests. Affected versions include those from 0.10.8 up to, but not including, 1.3.1. The resolution involves generating a unique nonce for each request, thereby enhancing the security posture of the application.
Affected Version(s)
ash_admin 0.10.8 < 1.3.1
ash_admin 99b8daed7b2f79d82fcd9e89338d41b0e1564aa7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
