The Table, DataTable, and Show components built row-action URLs by raw string interpolation, splicing the primary key (and table, domain, and resource names) into the query string without URL-encoding. Ash resources routinely use user-settable string primary keys (slugs, emails). Because Plug.Conn.Query resolves duplicate parameters last-wins and primary_key is interpolated last, a stored key such as foo&action_type=destroy injects parameters that override the link, so an admin clicking edit is sent to a destroy form or an arbitrary resource; a # truncates the query into a fragment. The fix builds every link with URI.encode_query/1, encoding all interpolated values.
This issue affects ash_admin: from 0.3.0-rc.0 before 1.3.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links. The Table, DataTable, and Show components built row-action URLs by raw string interpolation, splicing the primary key (and table, domain, and resource names) into the query string without URL-encoding. Ash resources routinely use user-settable string primary keys (slugs, emails). Because Plug.Conn.Query resolves duplicate parameters last-wins and primary_key is interpolated last, a stored key such as foo&action_type=destroy injects parameters that override the link, so an admin clicking edit is sent to a destroy form or an arbitrary resource; a # truncates the query into a fragment. The fix builds every link with URI.encode_query/1, encoding all interpolated values. This issue affects ash_admin: from 0.3.0-rc.0 before 1.3.1. | |
| Title | Query-parameter injection in AshAdmin row-action links via unencoded string primary keys | |
| First Time appeared |
Ash-project
Ash-project ash Admin |
|
| Weaknesses | CWE-116 | |
| CPEs | cpe:2.3:a:ash-project:ash_admin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ash-project
Ash-project ash Admin |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-08-31T02:26:05.357Z
Reserved: 2026-08-30T23:15:02.375Z
Link: CVE-2026-82681
No data.
Status : Received
Published: 2026-08-31T03:16:43.643
Modified: 2026-08-31T03:16:43.643
Link: CVE-2026-82681
No data.
OpenCVE Enrichment
Updated: 2026-08-31T03:30:05Z
-
CWE-116
Improper Encoding or Escaping of Output