Executive brief
AshPhoenix is a Phoenix framework integration library used to build forms and web interfaces. A vulnerability causes the library to write raw, unfiltered user input (including passwords and other secrets) into error messages that appear in application logs, crash reports, and development error pages. An attacker can intentionally submit malformed form data to trigger errors that leak sensitive information.
Technical details
The vulnerability is an information disclosure issue in AshPhoenix.Form.Auto's union sub-form handling. When a submitted _union_type parameter does not match a configured type, the error message is constructed using inspect(params, pretty: true), which embeds the full untrusted parameter map and internal union constraints. Because the message is built by the library rather than Phoenix's parameter logger, the standard config :phoenix, :filter_parameters configuration does not redact secrets. An attacker can submit malicious parameters (e.g., %{"_union_type" => "invalid", "password" => "secret123"}) to trigger an exception with the plaintext secret embedded in the message. The fix restricts error messages to report only the invalid _union_type value and valid type names, removing parameter and constraint dumps. Versions 1.2.17 through 2.3.24 are affected; patched in 2.3.25.
Affected products
- ash-project ash_phoenix 1.2.17 through 2.3.24
Timeline
- 2026-08-31: disclosed