Description
Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied.

When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in original_value because embedded resources must remain writable, and hides it from Inspect rather than removing it. AshTypescript.Rpc.ResultProcessor strips these markers to nil on its template-driven paths, but normalize_primitive/1 in lib/ash_typescript/rpc/result_processor.ex had no such clause, so a marker fell through to the generic struct branch which calls Map.from_struct/1 and serializes every key, original_value included. The denied value is returned to the caller inside the marker that represents its own denial.

The simplest trigger is an action returning an embedded resource as a map, which routes through normalize_resource_struct/2 with an empty template. normalize_value_for_json/1 is a public, unguarded entry point to the same path.

This issue affects ash_typescript: from 0.11.0 before 0.18.0.
Published: 2026-09-01
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in ash-typescript’s result processor. When a field policy denies an attribute, Ash substitutes a %Ash.ForbiddenField{} marker that preserves the real value in the original_value field. The normalize_primitive/1 code path does not strip this marker, so the value is serialized and returned to the caller, allowing an unauthorized RPC user to read data that should have been protected. This flaw results in unauthorized disclosure of sensitive attribute values.

Affected Systems

ash-project ash_typescript is affected in all releases from 0.11.0 up to but not including 0.18.0. Any deployment of these versions that exposes the RPC interface for returning embedded resources is vulnerable.

Risk and Exploitability

The CVSS score of 8.2 highlights a high-severity information‑disclosure issue. EPSS data is not available, so the exact probability of exploitation cannot be quantified, but the vulnerability is actionable through the public RPC endpoint. An attacker who can invoke RPC calls that return embedded resources, such as normalizing a value or processing a returned struct, can trigger the flaw and obtain forbidden field values. The attack is feasible over the network if the RPC service is exposed, making the risk significant for systems with less restrictive access controls. The vulnerability is not listed in CISA KEV, but the high CVSS score warrants timely remediation.

Generated by OpenCVE AI on September 1, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ash-typescript to version 0.18.0 or later where the result normalizer correctly handles forbidden field markers.
  • Restrict RPC access to authenticated and authorized callers, and limit or block actions that return embedded resources via the RPC interface.
  • If an upgrade cannot be performed immediately, modify the normalize_primitive/1 function to explicitly treat %Ash.ForbiddenField{} markers by setting the associated value to nil or removing the key before serialization to prevent disclosure.

Generated by OpenCVE AI on September 1, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in original_value because embedded resources must remain writable, and hides it from Inspect rather than removing it. AshTypescript.Rpc.ResultProcessor strips these markers to nil on its template-driven paths, but normalize_primitive/1 in lib/ash_typescript/rpc/result_processor.ex had no such clause, so a marker fell through to the generic struct branch which calls Map.from_struct/1 and serializes every key, original_value included. The denied value is returned to the caller inside the marker that represents its own denial. The simplest trigger is an action returning an embedded resource as a map, which routes through normalize_resource_struct/2 with an empty template. normalize_value_for_json/1 is a public, unguarded entry point to the same path. This issue affects ash_typescript: from 0.11.0 before 0.18.0.
Title Authorization-redacted field values disclosed through AshTypescript result normalization
First Time appeared Ash-project
Ash-project ash Typescript
Weaknesses CWE-863
CPEs cpe:2.3:a:ash-project:ash_typescript:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Typescript
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Typescript
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-01T02:09:01.851Z

Reserved: 2026-08-31T00:59:08.960Z

Link: CVE-2026-82730

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T03:16:52.787

Modified: 2026-09-01T03:16:52.787

Link: CVE-2026-82730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T03:30:04Z

Weaknesses