VDB
Sign up

EEF-CVE-2026-82673

Path traversal in AshAdmin file uploads via unsanitized client filename

Quick fix

EEF-CVE-2026-82673 — ash_admin: upgrade to the fixed version with the command below.

mix deps.update ash_admin

Details

## Summary

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server.

`AshAdmin.Components.Resource.Form.consume_file_uploads/1` builds the destination as `Path.join([tmp_dir, entry.client_name])` and writes it with `File.cp!/2`. `entry.client_name` is the browser-supplied filename and is not sanitized, and `Path.join/1` does not normalize `..`. An upload named `../../../../var/www/app/priv/static/x.png` therefore escapes the random temp directory and lands anywhere the BEAM user can write, enabling arbitrary file write and potentially remote code execution by overwriting application assets, configuration, or cron/ssh files. The only guard is an extension allowlist defaulting to `:any` that checks only the extension. The fix strips path components with `Path.basename/1` before joining.

This issue affects ash_admin: from 0.13.7 before 1.3.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/ash_admin
Introduced in: 0.13.7Fixed in: 1.3.1
Fixmix deps.update ash_admin

References