{"id":"CVE-2026-82730","aliases":["GHSA-6929-rjmh-4x62"],"url":"https://o3.security/vulnerability/CVE-2026-82730","summary":"Authorization-redacted field values disclosed through AshTypescript result normalization","details":"## Summary\n\nIncorrect Authorization vulnerability in ash-project ash\\_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied.\n\nWhen a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in original\\_value because embedded resources must remain writable, and hides it from Inspect rather than removing it. AshTypescript.Rpc.ResultProcessor strips these markers to nil on its template-driven paths, but normalize\\_primitive/1 in lib/ash\\_typescript/rpc/result\\_processor.ex had no such clause, so a marker fell through to the generic struct branch which calls Map.from\\_struct/1 and serializes every key, original\\_value included. The denied value is returned to the caller inside the marker that represents its own denial.\n\nThe simplest trigger is an action returning an embedded resource as a map, which routes through normalize\\_resource\\_struct/2 with an empty template. normalize\\_value\\_for\\_json/1 is a public, unguarded entry point to the same path.\n\nThis issue affects ash\\_typescript: from 0.11.0 before 0.18.0.\n\n## Configuration\n\nThe application exposes an AshTypescript RPC endpoint over HTTP and relies on Ash field policies to hide attributes on embedded resources that an action returns as a map.","published":"2026-09-01T02:09:01.851Z","modified":"2026-09-01T02:15:05.398862380Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Hex","name":"ash_typescript","fixedVersion":"0.18.0"}],"fix":{"url":"https://github.com/ash-project/ash_typescript/commit/aa7f9f1967b0bec806ac1156142267e805d70a55","label":"ash-project/ash_typescript@aa7f9f1"},"references":[{"type":"ADVISORY","url":"https://github.com/ash-project/ash_typescript/security/advisories/GHSA-6929-rjmh-4x62"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-82730.html"},{"type":"FIX","url":"https://github.com/ash-project/ash_typescript/commit/aa7f9f1967b0bec806ac1156142267e805d70a55"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_typescript"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-01T02:15:05.398862380Z"}}