PT-2026-83503 · Unknown · Ash Paper Trail

·

CVE-2026-75847

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash paper trail versions 0.1.1 through 0.6.9
Description Sensitive information is stored in cleartext within the generated version resource. An attacker with read access to this resource can recover the plaintext of attributes marked as sensitive. This occurs because the changes map in the version resource is declared as public and not sensitive, causing values to be returned by the default read action and appearing in logs, inspect output, and error messages without redaction. The AshPaperTrail.Resource.Transformers.CreateVersionResource function incorrectly derives the sensitivity of the changes map from the ignore attributes list instead of the tracked attributes. Since ignore attributes defaults to empty, the sensitivity flag remains false.
Recommendations Update ash paper trail to version 0.7.0 or later.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75847
GHSA-WQJR-XMXP-J554

Affected Products

Ash Paper Trail