ash_graphql is vulnerable to Information Disclosure
69
Medium Risk
AshGraphql's error handling re-injects the original :path field via Map.put_new/3 after a configured error_handler runs. This reverses any sanitization the handler performed, including explicit deletion of the path. Because build_error_path/5 defaults to internal Ash field names when no GraphQL field mapping exists, validation failures on non-exposed attributes leak internal field identifiers to any client submitting a failing request. The fix stops re-attaching the error path after the handler executes.
You are affected if you are using a version that falls within the vulnerable range.
ash_graphql is vulnerable to Information Disclosure in versions 1.9.0 - 1.10.1.
Upgrade the ash_graphql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.