This issue affects ash: from pkg:hex/ash before pkg:hex/ash@3.5.39, before 3.5.39, before 5d1b6a5d00771fd468a509778637527b5218be9a.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27096 | Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden |
Github GHSA |
GHSA-jj4j-x5ww-cwh9 | Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden |
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 08 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 07 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from pkg:hex/ash before pkg:hex/ash@3.5.39, before 3.5.39, before 5d1b6a5d00771fd468a509778637527b5218be9a. | |
| Title | Before action hooks may execute in certain scenarios despite a request being forbidden | |
| First Time appeared |
Ash-project
Ash-project ash |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ash-project
Ash-project ash |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-04-06T16:44:06.316Z
Reserved: 2025-05-15T08:40:25.455Z
Link: CVE-2025-48042
Updated: 2025-09-08T18:55:06.932Z
Status : Deferred
Published: 2025-09-07T16:15:51.240
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-48042
No data.
OpenCVE Enrichment
Updated: 2026-04-28T00:30:15Z
EUVD
Github GHSA