CVE Database
/

CVE-2025-48044

Back to search

CVE-2025-48044

Published: Oct 17, 2025

Modified: May 27, 2026

PUBLISHED

Description

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/[email protected] before pkg:hex/[email protected], from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.

VendorProductVersions

ash-project

ash

affected
3.6.3 - < 3.7.1

ash-project

ash

affected
79749c2685ea031ebb2de8cf60cc5edced6a8dd0 - < 8b83efa225f657bfc3656ad8ee8485f9b2de923d

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now