Improper Input Validation in Ash_Project Ash_TypeScript Product by Ash Project
CVE-2026-82732

6.3MEDIUM

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-82732?

The Ash_Project Ash_TypeScript product contains an improper input validation issue that allows remote attackers to submit argument values that fall outside declared allowlists or boundaries on typed-controller routes. The vulnerability arises from the misuse of Ash.Type.cast_input/3, which treats an {:ok, cast} result as fully validated without applying necessary constraints. Consequently, various constraints, such as one_of, max_length, and match, are rendered ineffective. This could result in potential privilege escalation and state-machine bypasses, as the application may accept unauthorized values leading to an insecure situation. The affected versions encompass those from 0.15.0 before 0.18.0.

Affected Version(s)

ash_typescript 0.15.0 < 0.18.0

ash_typescript 546a15e1a2d7dbf1df2d5a6ee4404bc3da87852e < 21ab6f1229a4dccdb56bc37ed437d9672a0c4a4e

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Torkild Gundersen Kjevik / Ash Project
Jonatan Männchen / EEF
.