Improper Protection of Alternate Path Vulnerability in Ash Project's Lua Plugin
CVE-2026-82586

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-82586?

The ash_lua plugin in the Ash Project is vulnerable due to improper protection mechanisms, allowing user-supplied Lua scripts to access unintended data attributes. The issue arises from the implementation of the read action in the AshLua.Runtime, which directly uses input from Lua calls to resolve field names. This bypasses the safeguards of the exposed-field allow-list. Consequently, an attacker capable of influencing Lua scripts can gain access to sensitive columns, including private data. The vulnerability affects ash_lua versions prior to 0.2.1, necessitating immediate attention to secure environments relying on this component.

Affected Version(s)

ash_lua 0.1.0 < 0.2.1

ash_lua 8675e47cca81f36594083a7e63379bac9e123e72

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.