Executive brief
ash_phoenix is a Phoenix/LiveView integration library for the Ash data framework, used to build web applications with multi-tenant support. The vulnerability allows tenant-scoped authorization checks to be bypassed by invoking them with a nil tenant value, potentially granting unauthorized access to data across tenant boundaries. This breaks the core tenant isolation mechanism that protects customer data in multi-tenant applications.
Technical details
The vulnerability is an incorrect authorization/timing flaw in AshPhoenix.LiveView.SubdomainHook.on_mount/4. The hook attempts to assign the tenant and immediately call handle_subdomain within on_mount, but LiveView does not execute handle_params (where the tenant assign is set) until after on_mount returns. Consequently, handle_subdomain runs with a nil tenant, causing authorization checks that verify tenant membership to either crash or take a permissive default path. These checks are never re-evaluated once the real tenant is assigned or on subsequent navigations. The fix moves handle_subdomain invocation into the handle_params hook where the tenant is properly available on every navigation. Affected versions: ash_phoenix 2.1.26 before 2.3.25.
Affected products
- ash-project ash_phoenix 2.1.26 to before 2.3.25
Timeline
- 2026-08-31: disclosed