Vulnerability description

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.

This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2.

This issue affects ash: from pkg:hex/ash@3.6.3 before pkg:hex/ash@3.7.1, from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.

Affected

ash-project / ash

Source File Routine
lib/ash/policy/policy.ex 'Elixir.Ash.Policy.Policy':expression/2
Status Version Changes / Fixed in
affected pkg:hex/ash@3.6.3 < pkg:hex/ash@3.7.1
affected 3.6.3 < 3.7.1
affected 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 < 8b83efa225f657bfc3656ad8ee8485f9b2de923d

References

Credits

  • Reporter: Jechol Lee
  • Remediation developer: Jechol Lee
  • Analyst: Jonatan Männchen
  • Remediation reviewer: Zach Daniel

CVE record as JSON:  GET /cves/CVE-2025-48044.json
OSV record as JSON:  GET /osv/EEF-CVE-2025-48044.json