Executive brief
ash_graphql is a GraphQL library for the Ash framework that developers use to build GraphQL APIs. A vulnerability in error handling allows remote attackers to read internal field names and system details that applications intended to keep hidden, potentially exposing sensitive schema information and aiding further attacks.
Technical details
The vulnerability exists in AshGraphql.Errors where error handling logic uses Map.put_new to merge the error_handler's sanitized response with an error path. Because put_new only uses the handler's :path value if already set, a sanitizing handler that deletes :path to redact information is circumvented—the deleted path is replaced with build_error_path/5's output. That function falls back to raw internal Ash attribute and argument names when no field_names mapping is configured, causing validation failures on non-exposed or nested fields to leak internal names in the GraphQL error response. The attack requires only network access to the GraphQL endpoint and does not require authentication. An attacker can discover unexposed schema fields and internal naming conventions by triggering validation errors.
Affected products
- ash-project ash_graphql from 1.9.0 before 1.11.0
Timeline
- 2026-08-30: disclosed