EEF-CVE-2026-82673
Path traversal in AshAdmin file uploads via unsanitized client filename
Quick fix
EEF-CVE-2026-82673 — ash_admin: upgrade to the fixed version with the command below.
mix deps.update ash_adminDetails
## Summary
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server.
`AshAdmin.Components.Resource.Form.consume_file_uploads/1` builds the destination as `Path.join([tmp_dir, entry.client_name])` and writes it with `File.cp!/2`. `entry.client_name` is the browser-supplied filename and is not sanitized, and `Path.join/1` does not normalize `..`. An upload named `../../../../var/www/app/priv/static/x.png` therefore escapes the random temp directory and lands anywhere the BEAM user can write, enabling arbitrary file write and potentially remote code execution by overwriting application assets, configuration, or cron/ssh files. The only guard is an extension allowlist defaulting to `:any` that checks only the extension. The fix strips path components with `Path.basename/1` before joining.
This issue affects ash_admin: from 0.13.7 before 1.3.1.
Are you affected?
Enter the version of the package you're using.