ash_admin
Hex7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_adminpage 1 of 1
- CVE-2026-75757HIGHCVSS 8.3EG 8.3✓ Fixed in 1.3.12026-08-31
vulnerable: 0.10.0 ... 1.3.0 (74 versions)
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin…
- CVE-2026-77850HIGHCVSS 8.4EG 8.4✓ Fixed in 1.3.12026-08-31
vulnerable: 0.13.0 ... 1.3.0 (32 versions)
Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser. The relationship typeahead components AshAdmin.Components.Resource.RelationshipField and…
- CVE-2026-81852LOWCVSS 2.1EG 2.1✓ Fixed in 1.3.12026-08-31
vulnerable: 0.10.10 ... 1.3.0 (58 versions)
Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without :csp_nonce_assign_key, AshAdmin.Router.…
- CVE-2026-81853LOWCVSS 2.3EG 2.3✓ Fixed in 1.3.12026-08-31
vulnerable: 0.1.0 ... 1.3.0 (119 versions)
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality oracle over sensitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the composite-primary-key f…
- CVE-2026-82673HIGHCVSS 8.3EG 8.3✓ Fixed in 1.3.12026-08-31
vulnerable: 0.13.10 ... 1.3.0 (25 versions)
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server. AshAdmin.Components.Resource.Form.consume_file_…
- CVE-2026-82681LOWCVSS 2.0EG 2.0✓ Fixed in 1.3.12026-08-31
vulnerable: 0.10.0 ... 1.3.0 (92 versions)
Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links. The Table, DataTable, and Show components built …
- CVE-2026-82722HIGHCVSS 8.3EG 8.3✓ Fixed in 1.3.12026-08-31
vulnerable: 0.1.0 ... 1.3.0 (119 versions)
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table and crash the entire node. Two LiveView event handlers interned atom…
Check whether ash_admin is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_admin CVEs against the assets you own.
Start Free Scan →