Open Redirect Vulnerability in ash_typescript by Ash Project
CVE-2026-82731

2.3LOW

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-82731?

An Open Redirect vulnerability in ash_typescript allows an attacker to manipulate a path-parameter value. By redirecting a client's request to an untrusted site, the attacker can gain access to sensitive information. The vulnerability arises from the lack of proper encoding in URL builders, allowing raw values, including malicious ones, to be processed unsafely. Attackers can exploit this flaw to reroute requests to a controlled malicious host, potentially compromising user credentials.

Affected Version(s)

ash_typescript 0.15.0 < 0.18.0

ash_typescript 6669e22ece34b4534e706a46d1842f01b68ee23a < 5165f752f5f92b755d946f2d1ce750ff69083ffc

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Torkild Gundersen Kjevik / Ash Project
Jonatan Männchen / EEF
.