← العودة للجدول
CVE-2026-82732
CVE-2026-82732 — Improper Input Validation vulnerability in ash-project ash_typescript allows a r
📅 2026-09-01
🟠 High 🔥 No NVD Vulnerability Vulnerability

📋 الوصف الكامل

Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescript.TypedController.RequestHandler in lib/ash_typescript/typed_controller/request_handler.ex calls Ash.Type.cast_input/3 and treats an {:ok, cast} result as fully validated. In Ash these are separate st

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-82732

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-82732 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←