ash_lua
Hex2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_luapage 1 of 1
- CVE-2026-78216MEDIUMCVSS 6.0EG 6.0✓ Fixed in 0.2.22026-09-08
vulnerable: 0.1.0 ... 0.2.1 (9 versions)
AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash fiel…
- CVE-2026-82586HIGHCVSS 8.2EG 8.2✓ Fixed in 0.2.12026-09-07
vulnerable: 0.1.0 ... 0.2.0 (8 versions)
Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest…
Check whether ash_lua is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_lua CVEs against the assets you own.
Start Free Scan →