ash_typescript is vulnerable to Information Exposure Through an Error Message
63
Medium Risk
The typed controller interpolates inspect(value, limit: 50) into the HTTP 500 response body when a route handler returns anything other than a %Plug.Conn{} struct. The limit option bounds elements per collection rather than the whole term, so an error tuple carrying a user record can serialize full field sets into the response, exposing hashed passwords, tokens, and tenant identifiers. Unlike other raised error paths this disclosure does not check the show-raised-errors setting. The fix only includes the unexpected return detail when that configuration is enabled.
You are affected if you are using a version that falls within the vulnerable range and you have typed controller route handlers that can return a non-connection term containing sensitive data.
ash_typescript is vulnerable to Information Exposure Through an Error Message in versions 0.15.0 - 0.17.3.
Upgrade the ash_typescript library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.