15 Total CVEs
15 AI Analyzed
0 CISA KEV
1 Critical

Profile

0% ended up actively exploited 0 of 15 added to CISA KEV
7% rated critical (CVSS 9.0+) 1 critical, 14 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

15 CVEs in the last 12 months

Products

  • ash_admin4
  • ash_ai4
  • ash_typescript3
  • ash_graphql2
  • ash_phoenix1
  • ash_postgres1

6 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-82730
Analyzed
8.2
ash-project ash_typescript

Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies...

2026-09-01
CVE-2026-82724
Analyzed
7.6
ash-project ash_phoenix

Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped...

2026-08-31
CVE-2026-82722
Analyzed
8.3
ash-project ash_admin

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust...

2026-08-31
CVE-2026-82673
Analyzed
8.3
ash-project ash_admin

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled...

2026-08-31
CVE-2026-82564
Analyzed
7.1
ash-project ash_ai

Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destr...

2026-08-31
CVE-2026-81636
Analyzed
8.7
ash-project ash_graphql

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configure...

2026-08-31
CVE-2026-81315
Analyzed
7.4
ash-project ash_ai

Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue...

2026-08-31
CVE-2026-80223
Analyzed
7.1
ash-project ash_graphql

Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records...

2026-08-31
CVE-2026-78699
Analyzed
7.2
ash-project ash_postgres

Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing...

2026-08-31
CVE-2026-77956
Analyzed
10
ash-project ash_ai

An unauthenticated code injection vulnerability in ash_ai allows remote attackers to execute arbitrary Elixir code by injecting malicious EEx template...

2026-08-31
CVE-2026-77856
Analyzed
8.2
ash-project ash_typescript

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEA...

2026-09-01
CVE-2026-77850
Analyzed
8.4
ash-project ash_admin

Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser....

2026-08-31
CVE-2026-75760
Analyzed
7.1
ash-project ash_ai

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a...

2026-08-31
CVE-2026-75757
Analyzed
8.3
ash-project ash_admin

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain...

2026-08-31
CVE-2026-74837
Analyzed
8.7
ash-project ash_typescript

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEA...

2026-09-01