Intel

AIKIDO-2026-112695

ash_phoenix is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive InformationCVE-2026-82727 Published Yesterday

23

Low Risk

This Affects:

ELIXIRash_phoenix
1.2.17 - 2.3.24
Fixed in 2.3.25
Are you affected? Scan for Free

TL;DR

AshPhoenix.Form.Auto builds an error for an unknown _union_type value submitted in a form by inspecting the entire raw param map for that form. Passwords, tokens and other secrets submitted alongside the union field are written verbatim into the exception message, which reaches logs, crash reports and the development error page. This bypasses Phoenix filter_parameters redaction. The fix stops emitting the raw submitted params in that error.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use AshPhoenix.Form auto-generated union forms that accept a user-submitted _union_type value.

Background info

ash_phoenix is vulnerable to Exposure of Sensitive Information in versions 1.2.17 - 2.3.24.

How to fix this

Upgrade the ash_phoenix library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform