Improper Protection of Alternate Path Vulnerability in Ash Project's Lua Plugin
CVE-2026-82586
What is CVE-2026-82586?
The ash_lua plugin in the Ash Project is vulnerable due to improper protection mechanisms, allowing user-supplied Lua scripts to access unintended data attributes. The issue arises from the implementation of the read action in the AshLua.Runtime, which directly uses input from Lua calls to resolve field names. This bypasses the safeguards of the exposed-field allow-list. Consequently, an attacker capable of influencing Lua scripts can gain access to sensitive columns, including private data. The vulnerability affects ash_lua versions prior to 0.2.1, necessitating immediate attention to secure environments relying on this component.
Affected Version(s)
ash_lua 0.1.0 < 0.2.1
ash_lua 8675e47cca81f36594083a7e63379bac9e123e72
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
