Description
AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value.

Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A script could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate instead of as a field. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The prior hardening only enforced the exposed-field allow-list (field visibility), which is a separate axis from per-actor field-policy authorization.

The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible.

This issue affects ash_lua: from 0.1.0 before 0.2.2.
Published: 2026-09-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data confidentiality breach via aggregate read
Action: Assess Impact
AI Analysis

Impact

A scripting interface in AshLua lets users execute arbitrary Lua code through an eval action. The read operation exposes an ability to request aggregate functions such as list, min, max, first, sum, and avg on a specified field. Because field‑policy enforcement removes forbidden data only from full record results, it does not apply to aggregate values, allowing scripts to retrieve values from fields that should be hidden by per‑actor policies. This effectively bypasses privacy controls and can expose sensitive personal information that is normally protected.

Affected Systems

AshProject’s AshLua component is affected, with vulnerable releases ranging from version 0.1.0 up to but excluding 0.2.2. The issue applies to all builds of ash_lua within that range.

Risk and Exploitability

The vulnerability scores a CVSS of 6 and the EPSS score is not available, indicating moderate severity and an unclear likelihood of exploitation. The Ash project has not listed it in the CISA KEV catalog. Exploitation requires the ability to run Lua code via eval, typically available to privileged users or an attacker who has compromised an instance of the application. Once a script is executed, the attacker can aggregate over fields that the caller’s policy would otherwise deny, thereby obtaining confidential data from the underlying database or data store.

Generated by OpenCVE AI on September 8, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AshLua to version 0.2.2 or later to enforce field‑policy checks on aggregate operations.
  • Restrict the use of the eval interface to trusted users or remove it entirely if not needed for your deployment.
  • Verify that all field policies correctly define visibility and authorization rules, and re‑audit them after applying the patch.

Generated by OpenCVE AI on September 8, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A script could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate instead of as a field. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The prior hardening only enforced the exposed-field allow-list (field visibility), which is a separate axis from per-actor field-policy authorization. The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2.
Title AshLua eval read operations can read field-policy-protected fields via aggregates
First Time appeared Ash-project
Ash-project ash Lua
Weaknesses CWE-1220
CPEs cpe:2.3:a:ash-project:ash_lua:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Lua
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Lua
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-08T17:27:08.856Z

Reserved: 2026-08-31T00:45:02.446Z

Link: CVE-2026-78216

cve-icon Vulnrichment

Updated: 2026-09-08T17:26:42.706Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T17:18:30.653

Modified: 2026-09-08T19:29:09.680

Link: CVE-2026-78216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:00:11Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control