SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77970

MEDIUM · CVSS 5.9 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ash_paper_trail component is vulnerable due to its inadequate handling of sensitive information, allowing attackers with read access to retrieve sensitive values from embedded resources, unions, or lists in cleartext. This vulnerability could lead to the exposure of critical data, such as tokens or credentials, which may compromise system security. Organizations using ash_paper_trail versions between 0.3.0 and 0.7.0 should prioritize remediation to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77970
Severity
MEDIUM
CVSS
5.9
EPSS
0.10%

Original NVD Description

Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore only act on the tracked resource's top-level attributes. maybe_redact_changes/3 and the stored-action-input path in AshPaperTrail.Resource.Changes.CreateNewVersion derive the sensitive set from the resource's own attributes and never descend into embedded, union, or list values, so a non-sensitive attribute or action argument that holds an embed with a sensitive? field (for example an accepted credentials embed carrying a token) is written to the version table in cleartext. This issue affects ash_paper_trail: from 0.3.0 before 0.7.0.