PT-2026-83691 · Unknown · Ash Phoenix

·

CVE-2026-82727

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash phoenix versions 1.2.17 through 2.3.24
Description The software writes the entire raw submitted parameter map into an exception message when AshPhoenix.Form.Auto builds a union sub-form and the submitted union type does not match a configured type. This causes sensitive information, such as secrets submitted alongside a union form field, to leak into logs, crash reports, and development error pages. Because the message is constructed by the library instead of the Phoenix parameter logger, the filter parameters configuration does not redact the data. An attacker can trigger this by submitting an invalid union type along with sensitive data in other parameters, such as password, which will then be included verbatim in the raised message.
Recommendations Update ash phoenix to version 2.3.25 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82727
GHSA-5XF4-HGCQ-XW7V

Affected Products

Ash Phoenix