Improper Input Validation in Ash_Project Ash_TypeScript Product by Ash Project
CVE-2026-82732
What is CVE-2026-82732?
The Ash_Project Ash_TypeScript product contains an improper input validation issue that allows remote attackers to submit argument values that fall outside declared allowlists or boundaries on typed-controller routes. The vulnerability arises from the misuse of Ash.Type.cast_input/3, which treats an {:ok, cast} result as fully validated without applying necessary constraints. Consequently, various constraints, such as one_of, max_length, and match, are rendered ineffective. This could result in potential privilege escalation and state-machine bypasses, as the application may accept unauthorized values leading to an insecure situation. The affected versions encompass those from 0.15.0 before 0.18.0.
Affected Version(s)
ash_typescript 0.15.0 < 0.18.0
ash_typescript 546a15e1a2d7dbf1df2d5a6ee4404bc3da87852e < 21ab6f1229a4dccdb56bc37ed437d9672a0c4a4e
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
