CVE-2026-67579Patch(ash-hq / ash_framework)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ash-hq ash_framework systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset pagination decode the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex using non_executable_binary_to_term/2 with [:safe]. That guard blocks new atoms, funs, and ports, but not a struct built from atoms already interned in a running Ash application, so a decoded %Ash.Query.Call{} expression survives and is spliced into the keyset filter as a comparison value in do_filters/4 and evaluated. Because the cursor bypasses the Ash.Expr macro, the runtime never applies the private?/public? gate that would otherwise reject it. On AshPostgres the injected fragment is inlined into the SQL query; on the ETS and Simple data layers it is evaluated in-process as an arbitrary function call. This issue affects ash: from 1.17.0 before 3.31.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ash_framework

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ash_framework

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-12: 108-12
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Zach Daniel@ZachSDaniel1
    Patch

    We have a serious CVE for #AshFramework. If you are using #AshFramework please update to the latest version as soon as you can. https://cna.erlef.org/cves/CVE-2026-67579.html

    Post summary

    A serious CVE affecting AshFramework has been disclosed; users are advised to update to the latest version to mitigate the vulnerability.

    02926675.1K
    3.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appash-hqash_framework---

Explore more