PT-2026-83505 · Unknown · Ash Paper Trail

·

CVE-2026-77970

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash paper trail versions 0.3.0 through 0.6.9
Description Sensitive information is stored in cleartext within the version table. An attacker with read access to the generated version resource can recover sensitive values nested inside embedded resources, unions, or lists. This occurs because the sensitive attributes :redact and :ignore settings only apply to top-level attributes of the tracked resource. Specifically, the maybe redact changes/3 function and the stored-action-input path in AshPaperTrail.Resource.Changes.CreateNewVersion do not descend into embedded, union, or list values. Consequently, if a non-sensitive attribute or action argument contains an embed with a sensitive field, such as a token within accepted credentials, it is recorded without redaction.
Recommendations Update ash paper trail to version 0.7.0 or later.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77970
GHSA-V645-6JM6-CGPJ

Affected Products

Ash Paper Trail