Intel

AIKIDO-2026-245326

ash_phoenix is vulnerable to Authorization Bypass Through User-Controlled Key

Authorization Bypass Through User-Controlled KeyCVE-2026-82725 Published Yesterday

23

Low Risk

This Affects:

ELIXIRash_phoenix
0.6.0 - 2.3.24
Fixed in 2.3.25
Are you affected? Scan for Free

TL;DR

AshPhoenix.FilterForm resolves filter path segments with Ash.Resource.Info.related/2 instead of Ash.Resource.Info.public_relationship/2, validating only the publicity of the terminal field. User-controlled filter form parameters can therefore traverse private relationships during path resolution. This lets a form consumer filter across non-public relationships and disclose private related data. The fix rejects filtering across non-public relationships.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you expose AshPhoenix.FilterForm to user-controlled filter parameters.

Background info

ash_phoenix is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.6.0 - 2.3.24.

How to fix this

Upgrade the ash_phoenix library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform