Authorization Bypass Vulnerability in Ash Phoenix by Ash Project
CVE-2026-82725
What is CVE-2026-82725?
The Ash Phoenix product from the Ash Project contains a vulnerability that allows an attacker to bypass authorization controls through user-controlled filter form parameters. This flaw enables an attacker to access relationships that the resource author has marked as non-public, effectively turning the affected queries into a boolean oracle that can expose private related data. The vulnerability arises from the way Ash Phoenix resolves user-supplied paths and fields, failing to enforce proper visibility checks on non-terminal relationships. The impact of this security issue underscores the importance of rigorous input validation and access control mechanisms in modern web applications.
Affected Version(s)
ash_phoenix 0.6.0-rc.1 < 2.3.25
ash_phoenix 06875682999938f607c970e71b6a80af90e18b3d
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
