Incorrect Authorization in Ash-Typescript Affects Data Privacy
CVE-2026-82730
8.2HIGH
What is CVE-2026-82730?
A flaw in the ash_typescript library allows unauthorized RPC callers to access attribute values that should be denied by Ash field policies. This occurs due to improper handling of denied fields where the original values are not completely stripped but are presented through misleading markers. As a result, unauthorized users can inadvertently obtain sensitive data, undermining the intended access controls. The vulnerability is triggered when functions return embedded resources without adequate templates, exposing sensitive data through the Map.from_struct method.
Affected Version(s)
ash_typescript 0.11.0 < 0.18.0
ash_typescript 9cade7661a01b6e4d940386f482f48d148dbb1e6
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Peter Ullrich
Torkild Gundersen Kjevik / Ash Project
Jonatan Männchen / EEF
