EEF-CVE-2026-82730

Source
https://cna.erlef.org/osv/EEF-CVE-2026-82730.html
Import Source
https://cna.erlef.org/osv/EEF-CVE-2026-82730.json
JSON Data
https://api.osv.dev/v1/vulns/EEF-CVE-2026-82730
Aliases
Published
2026-09-01T02:09:01.851Z
Modified
2026-09-01T02:25:36.415960846Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Authorization-redacted field values disclosed through AshTypescript result normalization
Details

Summary

Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied.

When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in original_value because embedded resources must remain writable, and hides it from Inspect rather than removing it. AshTypescript.Rpc.ResultProcessor strips these markers to nil on its template-driven paths, but normalize_primitive/1 in lib/ash_typescript/rpc/result_processor.ex had no such clause, so a marker fell through to the generic struct branch which calls Map.from_struct/1 and serializes every key, original_value included. The denied value is returned to the caller inside the marker that represents its own denial.

The simplest trigger is an action returning an embedded resource as a map, which routes through normalize_resource_struct/2 with an empty template. normalize_value_for_json/1 is a public, unguarded entry point to the same path.

This issue affects ash_typescript: from 0.11.0 before 0.18.0.

Configuration

The application exposes an AshTypescript RPC endpoint over HTTP and relies on Ash field policies to hide attributes on embedded resources that an action returns as a map.

Database specific
{
    "cpe_ids": [
        "cpe:2.3:a:ash-project:ash_typescript:*:*:*:*:*:*:*:*"
    ],
    "capec_ids": [
        "CAPEC-122"
    ],
    "cwe_ids": [
        "CWE-863"
    ]
}
References
Credits
    • Peter Ullrich - FINDER
    • Peter Ullrich - REPORTER
    • Torkild Gundersen Kjevik / Ash Project - REMEDIATION_DEVELOPER
    • Jonatan Männchen / EEF - COORDINATOR

Affected packages

Hex / ash_typescript

Package

Name
ash_typescript
Purl
pkg:hex/ash_typescript

Affected ranges

Type
SEMVER
Events
Introduced
0.11.0
Fixed
0.18.0

Affected versions

0.*
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.11.5
0.11.6
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.17.0
0.17.1
0.17.2
0.17.3

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-82730.json"

Git / github.com/ash-project/ash_typescript

Affected ranges

Type
GIT
Repo
https://github.com/ash-project/ash_typescript
Events

Affected versions

v0.*
v0.11.0
v0.11.1
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.11.6
v0.12.0
v0.12.1
v0.13.0
v0.13.1
v0.13.2
v0.14.0
v0.14.1
v0.14.2
v0.14.3
v0.14.4
v0.15.0
v0.15.1
v0.15.2
v0.15.3

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-82730.json"