πŸ” CVE Alert

CVE-2026-93477

UNKNOWN 0.0

Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments declared with public?: false are meant to be set only by trusted server-side code (for example via Ash.Changeset.set_private_argument/3) and must not be settable from end-user input. CVE-2026-55736 fixed the non-bulk changeset path to strip private arguments from user-supplied parameter maps, but the bulk destroy and bulk update paths were not covered. Ash.Actions.Destroy.Bulk.base_changeset/5 and Ash.Actions.Update.Bulk.base_changeset/5 match every key in the caller-supplied parameter map against all of the action's arguments with no public? check, then apply the matches to the base changeset. A caller who can submit parameters to a bulk destroy or bulk update action (for example through AshJsonApi, AshGraphql, or a controller that forwards request parameters to Ash.bulk_destroy/4 or Ash.bulk_update/4) can therefore set any private argument of that action, including one referenced by an arg(...) template in the action's changes or validations. Depending on how the application uses the argument (for example an acting_user_id driving authorization or record ownership, or audit metadata), this can lead to an integrity violation or privilege escalation. The fix requires public? in the argument matching on both bulk paths; private arguments remain settable server-side via the :private_arguments option. This issue affects ash: from 2.17.15 before 3.33.11.

CWE CWE-915
Vendor ash-project
Product ash
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for ash-project ash

Be the first to know when new unknown vulnerabilities affecting ash-project ash are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

ash-project / ash
2.17.15 < 3.33.11
ash-project / ash
8c17434803b2e91de522bdfbd0ca918e5d5898df < 6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/ash-project/ash/security/advisories/GHSA-c2p4-p7q6-hr2j cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-93477.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-93477 github.com: https://github.com/ash-project/ash/commit/8c17434803b2e91de522bdfbd0ca918e5d5898df github.com: https://github.com/ash-project/ash/commit/6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f

Credits

zx πŸ” zx Zach Daniel / Ash Project Jonatan MΓ€nnchen / EEF