Vulnerability description

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.

This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2.

This issue affects ash: from pkg:hex/ash@3.6.3 before pkg:hex/ash@3.7.1, from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.

Affected

pkg:hex/ash

Status Type Version Changes / Fixed in
affected semver 3.6.3 < 3.7.1

pkg:github/ash-project/ash

Source File Routine
lib/ash/policy/policy.ex Ash.Policy.Policy.expression/2
Status Type Version Changes / Fixed in
affected git 79749c2685ea < 8b83efa225f6

References

Credits

  • Reporter: Jechol Lee
  • Remediation developer: Jechol Lee
  • Analyst: Jonatan Männchen
  • Remediation reviewer: Zach Daniel

CVE record as JSON:  GET /cves/CVE-2025-48044.json
OSV record as JSON:  GET /osv/EEF-CVE-2025-48044.json