Intel

AIKIDO-2026-392058

ash is vulnerable to Information Exposure Through an Error Message

Information Exposure Through an Error MessageCVE-2026-82739 Published 2 days ago

21

Low Risk

This Affects:

ELIXIRash
2.17.20 - 3.32.1
Fixed in 3.32.2
Are you affected? Scan for Free

TL;DR

The confirm validation uses the stored field value in the atomic mismatch error instead of the submitted confirmation value. When the confirmation does not match, the error message discloses the stored value, including fields protected by field policies. Authenticated users can read data they are not authorized to see by triggering the mismatch. The fix uses the confirmation input instead of the stored value when building the error.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the confirm validation on a field protected by field policies during atomic updates.

Background info

ash is vulnerable to Information Exposure Through an Error Message in versions 2.17.20 - 3.32.1.

How to fix this

Upgrade the ash library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform