Executive brief
AshPhoenix is a web framework library used to build data-driven web applications in Elixir. A vulnerability in its filter form processing allows attackers to bypass authorization checks and access private related data by crafting malicious filter parameters, essentially turning the application into an oracle that leaks sensitive information about relationships the application intended to keep hidden.
Technical details
The vulnerability exists in AshPhoenix.FilterForm's path parsing logic, which failed to enforce authorization when filtering across relationships. The parse_path_and_field/2 function resolved every relationship hop using Ash.Resource.Info.related/2 (which traverses private relationships) and only checked the terminal field for publicity, rather than validating each hop. Additionally, field parameters naming private relationships were rewritten into extra path segments, bypassing checks. Since path and field parameters come directly from form input without the public-only enforcement of Ash.Filter.parse_input/2, attackers could construct filters that leak boolean information about private related data. The fix enforces public_relationship/2 at each hop and requires the terminal field to be public.
Affected products
- ash-project ash_phoenix 0.6.0-rc.1 before 2.3.25
Timeline
- 2026-08-31: disclosed