Incorrect Authorization in Ash-Typescript Affects Data Privacy
CVE-2026-82730

8.2HIGH

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-82730?

A flaw in the ash_typescript library allows unauthorized RPC callers to access attribute values that should be denied by Ash field policies. This occurs due to improper handling of denied fields where the original values are not completely stripped but are presented through misleading markers. As a result, unauthorized users can inadvertently obtain sensitive data, undermining the intended access controls. The vulnerability is triggered when functions return embedded resources without adequate templates, exposing sensitive data through the Map.from_struct method.

Affected Version(s)

ash_typescript 0.11.0 < 0.18.0

ash_typescript 9cade7661a01b6e4d940386f482f48d148dbb1e6

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Torkild Gundersen Kjevik / Ash Project
Jonatan Männchen / EEF
.