Intel

AIKIDO-2026-308240

ash_admin is vulnerable to Query Parameter Injection

Query Parameter InjectionCVE-2026-82681 Published Yesterday

20

Low Risk

This Affects:

ELIXIRash_admin
0.4.0 - 1.3.0
Fixed in 1.3.1
Are you affected? Scan for Free

TL;DR

AshAdmin builds row-action navigation links by interpolating a record's string primary key directly into the query string without URL-encoding it. A primary key value containing query-string metacharacters injects additional parameters into the generated link. Because later parameters win when the query string is parsed, the injected values can override the intended action an admin follows from the data table. The fix URL-encodes row-action link parameters.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you expose AshAdmin resources with string primary keys whose values can contain user-controlled characters.

Background info

ash_admin is vulnerable to Query Parameter Injection in versions 0.4.0 - 1.3.0.

How to fix this

Upgrade the ash_admin library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform