Intel

AIKIDO-2026-127545

ash is vulnerable to Mass Assignment

Mass AssignmentCVE-2026-93477 Published Yesterday

59

Medium Risk

This Affects:

ELIXIRash
2.17.15 - 3.33.10
Fixed in 3.33.11
Are you affected? Scan for Free

TL;DR

Ash's bulk destroy and bulk update actions build their base changeset by matching every key in the caller-supplied parameter map against all of an action's arguments, with no check for public?: false. A caller that can submit parameters to a bulk destroy or update action can therefore set a private argument that feeds an arg(...) template used by a change or validation, overriding a value the application intended to control only server-side. This is the bulk-path analog of an earlier fix that added the same check to the non-bulk changeset path. The fix requires arg.public? before an argument name is matched against user-supplied input in both bulk base_changeset functions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you define a private (public?: false) argument on a bulk destroy or update action that a change or validation references through an arg(...) template.

Background info

ash is vulnerable to Mass Assignment in versions 2.17.15 - 3.33.10.

How to fix this

Upgrade the ash library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform