EEF-CVE-2026-82673

Source
https://cna.erlef.org/osv/EEF-CVE-2026-82673.html
Import Source
https://cna.erlef.org/osv/EEF-CVE-2026-82673.json
JSON Data
https://api.osv.dev/v1/vulns/EEF-CVE-2026-82673
Aliases
Published
2026-08-31T02:33:10Z
Modified
2026-09-08T03:45:06Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N CVSS Calculator
Summary
Path traversal in AshAdmin file uploads via unsanitized client filename
Details

Summary

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server.

AshAdmin.Components.Resource.Form.consume_file_uploads/1 builds the destination as Path.join([tmp_dir, entry.client_name]) and writes it with File.cp!/2. entry.client_name is the browser-supplied filename and is not sanitized, and Path.join/1 does not normalize ... An upload named ../../../../var/www/app/priv/static/x.png therefore escapes the random temp directory and lands anywhere the BEAM user can write, enabling arbitrary file write and potentially remote code execution by overwriting application assets, configuration, or cron/ssh files. The only guard is an extension allowlist defaulting to :any that checks only the extension. The fix strips path components with Path.basename/1 before joining.

This issue affects ash_admin: from 0.13.7 before 1.3.1.

Database specific
{
    "capec_ids": [
        "CAPEC-126"
    ],
    "cpe_ids": [
        "cpe:2.3:a:ash-project:ash_admin:*:*:*:*:*:*:*:*"
    ],
    "cwe_ids": [
        "CWE-22"
    ]
}
References
Credits
    • Peter Ullrich - FINDER
    • Peter Ullrich - REPORTER
    • Zach Daniel / Ash Project - REMEDIATION_DEVELOPER
    • Jonatan Männchen / EEF - COORDINATOR

Affected packages

Hex / ash_admin

Package

Name
ash_admin
Purl
pkg:hex/ash_admin

Affected ranges

Type
SEMVER
Events
Introduced
0.13.7
Fixed
1.3.1

Affected versions

0.*
0.13.7
0.13.8
0.13.9
0.13.10
0.13.11
0.13.12
0.13.13
0.13.14
0.13.15
0.13.16
0.13.17
0.13.18
0.13.19
0.13.20
0.13.21
0.13.22
0.13.23
0.13.24
0.13.25
0.13.26
0.14.0
1.*
1.0.0-rc.0
1.1.0
1.2.0
1.3.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-82673.json"

Git / github.com/ash-project/ash_admin

Affected ranges

Type
GIT
Repo
https://github.com/ash-project/ash_admin
Events

Affected versions

v0.*
v0.13.10
v0.13.11
v0.13.12
v0.13.13
v0.13.14
v0.13.15
v0.13.16
v0.13.17
v0.13.18
v0.13.19
v0.13.20
v0.13.21
v0.13.22
v0.13.23
v0.13.24
v0.13.25
v0.13.26
v0.13.7
v0.13.8
v0.13.9
v0.14.0
v1.*
v1.1.0
v1.2.0
v1.3.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-82673.json"