PT-2026-83676 · Ash Admin · Ash Admin
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash admin versions 0.9.1 through 1.3.0
Description
An issue exists where the client JavaScript reads state cookies—specifically
tenant, actor resource, actor primary key, actor action, actor domain, actor authorizing, and actor paused—using an unanchored regular expression against document.cookie. This allows any cookie whose name ends with the requested name to match. Consequently, an attacker controlling a sibling subdomain can set a shadowing cookie with a broader domain (e.g., .example.com) that flows unvalidated into the LiveSocket connect parameters, enabling the rebinding of an admin session to a different actor, tenant, or authorization mode.Recommendations
Update ash admin to version 1.3.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash Admin