Improper Control of Object Attributes in Ash Project by Ash Vendor
CVE-2026-93477
What is CVE-2026-93477?
The vulnerability arises from the inadequate handling of private action arguments in bulk destroy and bulk update operations of the Ash Project. Attackers can exploit this flaw to manipulate private arguments that should only be set by trusted server-side code. This could potentially lead to serious security issues, including integrity violations and privilege escalations, as unauthorized users might gain control over critical application components. The recommended fix necessitates strict checks on public attributes in matching parameters, ensuring that private arguments remain secure and can only be modified server-side.
Affected Version(s)
ash 2.17.15 < 3.33.11
ash 8c17434803b2e91de522bdfbd0ca918e5d5898df < 6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
