ash_lua
Use your Ash actions in lua scripts via https://hexdocs.pm/lua. See the docs at https://hexdocs.pm/ash_lua
Activity
- Latest release
- 5d ago
- Total releases
- 10
- Cadence
- ~2 days
- Last 12 months
- 10
Reach
- Downloads
- 11.8k
- Stars
- 15
Details
- License
- MIT
- First release
- May 18, 2026
| Version | Released | |
|---|---|---|
0.2.2
patch
| ||
0.2.1
patch
1 CVE
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82586
EEF-CVE-2026-82586
GHSA-37jv-wc37-fhcw
Sep 07, 2026
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
High
Network
Low
None
None
SummaryImproper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The This issue affects ash_lua: from 0.1.0 before 0.2.1. ConfigurationsReachable only when an application exposes AshLua scripting (the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
Fixed in
0.2.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.6
patch
2 CVEs
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82586
EEF-CVE-2026-82586
GHSA-37jv-wc37-fhcw
Sep 07, 2026
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
High
Network
Low
None
None
SummaryImproper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The This issue affects ash_lua: from 0.1.0 before 0.2.1. ConfigurationsReachable only when an application exposes AshLua scripting (the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
Fixed in
0.2.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.5
patch
2 CVEs
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82586
EEF-CVE-2026-82586
GHSA-37jv-wc37-fhcw
Sep 07, 2026
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
High
Network
Low
None
None
SummaryImproper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The This issue affects ash_lua: from 0.1.0 before 0.2.1. ConfigurationsReachable only when an application exposes AshLua scripting (the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
Fixed in
0.2.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.4
patch
2 CVEs
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82586
EEF-CVE-2026-82586
GHSA-37jv-wc37-fhcw
Sep 07, 2026
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
High
Network
Low
None
None
SummaryImproper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The This issue affects ash_lua: from 0.1.0 before 0.2.1. ConfigurationsReachable only when an application exposes AshLua scripting (the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
Fixed in
0.2.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.3
patch
2 CVEs
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82586
EEF-CVE-2026-82586
GHSA-37jv-wc37-fhcw
Sep 07, 2026
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
High
Network
Low
None
None
SummaryImproper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The This issue affects ash_lua: from 0.1.0 before 0.2.1. ConfigurationsReachable only when an application exposes AshLua scripting (the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
Fixed in
0.2.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.2
patch
2 CVEs
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82586
EEF-CVE-2026-82586
GHSA-37jv-wc37-fhcw
Sep 07, 2026
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
High
Network
Low
None
None
SummaryImproper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The This issue affects ash_lua: from 0.1.0 before 0.2.1. ConfigurationsReachable only when an application exposes AshLua scripting (the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
Fixed in
0.2.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82586
EEF-CVE-2026-82586
GHSA-37jv-wc37-fhcw
Sep 07, 2026
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
High
Network
Low
None
None
SummaryImproper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The This issue affects ash_lua: from 0.1.0 before 0.2.1. ConfigurationsReachable only when an application exposes AshLua scripting (the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
Fixed in
0.2.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2026-78216
EEF-CVE-2026-78216
GHSA-5whv-8rcp-x33j
Sep 08, 2026
AshLua eval read operations can read field-policy-protected fields via aggregates
High
Network
Low
Low
None
SummaryAshLua exposes Ash read actions to Lua scripts run through an Ash field policies redact forbidden fields on returned records (replacing them with The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2. ConfigurationsReachable only when an application exposes an AshLua Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
Fixed in
0.2.2
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-82586
EEF-CVE-2026-82586
GHSA-37jv-wc37-fhcw
Sep 07, 2026
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
High
Network
Low
None
None
SummaryImproper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The This issue affects ash_lua: from 0.1.0 before 0.2.1. ConfigurationsReachable only when an application exposes AshLua scripting (the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
Fixed in
0.2.1
References Updated Sep 08, 2026 · Source: OSV.dev |