CVE-2025-48042: Ash-Project Ash

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.

Affected products

  • Ash-Project Ash: from 0.1.1, before 3.5.39 (fixed in 3.5.39)

Published 2025-09-07. Last modified 2026-09-22.