PT-2026-98374 · Ash · Ash
CVE-2026-93477
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
5.9
Medium
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash versions 2.17.15 through 3.33.10
Description
An Improperly Controlled Modification of Dynamically-Determined Object Attributes allows users to set values for private action arguments during bulk destroy and bulk update operations. Arguments marked with
public?: false are intended to be restricted to trusted server-side code and should not be modifiable via end-user input. The functions Ash.Actions.Destroy.Bulk.base changeset/5 and Ash.Actions.Update.Bulk.base changeset/5 fail to verify the public? attribute when matching keys from user-supplied parameter maps. Consequently, an attacker providing parameters to bulk destroy or bulk update actions—via AshJsonApi, AshGraphql, or controllers forwarding to Ash.bulk destroy/4 or Ash.bulk update/4—can manipulate private arguments. If these arguments, such as acting user id, are used for authorization, record ownership, or audit metadata, this can result in privilege escalation or integrity violations.Recommendations
Update ash to version 3.33.11 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash