Open Redirect Vulnerability in ash_typescript by Ash Project
CVE-2026-82731
2.3LOW
What is CVE-2026-82731?
An Open Redirect vulnerability in ash_typescript allows an attacker to manipulate a path-parameter value. By redirecting a client's request to an untrusted site, the attacker can gain access to sensitive information. The vulnerability arises from the lack of proper encoding in URL builders, allowing raw values, including malicious ones, to be processed unsafely. Attackers can exploit this flaw to reroute requests to a controlled malicious host, potentially compromising user credentials.
Affected Version(s)
ash_typescript 0.15.0 < 0.18.0
ash_typescript 6669e22ece34b4534e706a46d1842f01b68ee23a < 5165f752f5f92b755d946f2d1ce750ff69083ffc
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Peter Ullrich
Torkild Gundersen Kjevik / Ash Project
Jonatan Männchen / EEF
