PT-2025-42599 · Ash · Ash

Jechol Lee

+2

·

Published

2025-10-17

·

Updated

2025-10-21

·

CVE-2025-48044

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash versions 3.6.3 through 3.7.1
Description An incorrect authorization issue exists in ash, potentially allowing authentication bypass. The issue is associated with the lib/ash/policy/policy.ex file and the Elixir.Ash.Policy.Policy:expression/2 function.
Recommendations Update to ash version 3.7.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48044
GHSA-PCXQ-FJP3-R752

Affected Products

Ash