Threat Advisory

Ash Fails to Strip Private Action Arguments from Untrusted Input

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-55736 is a medium severity vulnerability affecting ash versions >= 3.0.0, < 3.29.3 in Ash with a CVSS score of 5.9, allowing an attacker to set private action arguments via string-keyed parameters and atomic changesets, potentially leading to integrity violations or privilege escalation when these arguments drive authorization, identity, or record ownership. The flaw exists due to incomplete filtering in the component responsible for building changesets from untrusted parameter maps, impacting all versions of Ash prior to 3.29.3. An attacker who can submit parameters to an action that defines a private argument can set that argument to a value of their choosing, overriding data the application intended to control server-side. This vulnerability has significant business impact as it allows unauthorized access and modification of sensitive data.

RECOMMENDATION:

We recommend you to update Ash to version 3.29.3.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-55736 is a medium severity vulnerability affecting ash versions >= 3.0.0, < 3.29.3 in Ash with a CVSS score of 5.9, allowing an attacker to set private action arguments via string-keyed parameters and atomic changesets, potentially leading to integrity violations or privilege escalation when these arguments drive authorization, identity, or record ownership. The flaw exists due to incomplete filtering in the component responsible for building changesets from untrusted parameter maps, impacting all versions of Ash prior to 3.29.3. An attacker who can submit parameters to an action that defines a private argument can set that argument to a value of their choosing, overriding data the application intended to control server-side. This vulnerability has significant business impact as it allows unauthorized access and modification of sensitive data.

RECOMMENDATION:

We recommend you to update Ash to version 3.29.3.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu