Sensitive Information Exposure in ash_typescript by Ash Project
CVE-2026-82733

6.3MEDIUM

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-82733?

The ash_typescript library for Elixir contains a vulnerability that allows unauthenticated attackers to access sensitive internal application data via HTTP 500 error responses. Specifically, when a typed-controller route handler returns a value other than the expected format, the application inadvertently exposes data. This occurs when the response includes the output of inspected values, which could unintentionally serialize sensitive information such as hashed passwords, tokens, and tenant identifiers. Critical measures outlined elsewhere in the module to restrict such outputs do not apply in this specific error handling path, leading to potential data leaks.

Affected Version(s)

ash_typescript 0.15.0 < 0.18.0

ash_typescript 546a15e1a2d7dbf1df2d5a6ee4404bc3da87852e

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Torkild Gundersen Kjevik / Ash Project
Jonatan Männchen / EEF
.