ash_admin is vulnerable to Path Traversal
83
High Risk
AshAdmin builds the destination path for uploaded files by joining a temporary directory with the browser-supplied file name without sanitizing it. A file name containing directory-traversal sequences escapes the temporary directory and writes to arbitrary locations the server process can reach. Because validation only checks the file extension, a traversal payload ending in an allowed extension still passes, enabling overwrite of application assets or configuration and potential code execution. The fix strips path components from uploaded file names before joining.
You are affected if you are using a version that falls within the vulnerable range and you expose AshAdmin forms with file-upload fields to users you do not fully trust.
ash_admin is vulnerable to Path Traversal in versions 0.13.7 - 1.3.0.
Upgrade the ash_admin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.