Sensitive Information Exposure in ash_typescript by Ash Project
CVE-2026-82733
What is CVE-2026-82733?
The ash_typescript library for Elixir contains a vulnerability that allows unauthenticated attackers to access sensitive internal application data via HTTP 500 error responses. Specifically, when a typed-controller route handler returns a value other than the expected format, the application inadvertently exposes data. This occurs when the response includes the output of inspected values, which could unintentionally serialize sensitive information such as hashed passwords, tokens, and tenant identifiers. Critical measures outlined elsewhere in the module to restrict such outputs do not apply in this specific error handling path, leading to potential data leaks.
Affected Version(s)
ash_typescript 0.15.0 < 0.18.0
ash_typescript 546a15e1a2d7dbf1df2d5a6ee4404bc3da87852e
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
