Back to search
CVE-2025-48043
Published: Oct 10, 2025
Modified: May 27, 2026
PUBLISHED
Description
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2. This issue affects ash: from pkg:hex/ash@0 before pkg:hex/[email protected], before 3.6.2, before 66d81300065b970da0d2f4528354835d2418c7ae.
| Vendor | Product | Versions |
|---|---|---|
ash-project | ash | affected 0 - < 3.6.2 |
ash-project | ash | affected 0 - < 66d81300065b970da0d2f4528354835d2418c7ae |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now