PT-2026-83677 · Ash Admin · Ash Admin

·

CVE-2026-77850

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash admin versions 0.13.0 through 1.3.0
Description A stored Cross-site Scripting (XSS) issue exists where attacker-supplied record content is executed as a script in an administrator's browser. The relationship typeahead components AshAdmin.Components.Resource.RelationshipField and AshAdmin.Components.Resource.ManagedRelationshipSelectField highlight search terms by wrapping them in <b> tags and rendering the string using the Phoenix.HTML.raw/1 function. Since raw/1 disables output escaping, a malicious label stored in the label field can execute JavaScript when a matching record appears in the dropdown, allowing an attacker to gain the administrator's privileges.
Recommendations Update ash admin to version 1.3.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77850
GHSA-M23X-576H-73W8

Affected Products

Ash Admin