What is CVE-2026-70395?
This vulnerability in the 'ash' component of the ash-proje project allows an attacker to forge a relationship with a record they cannot identify by name and recover the secret value used for its lookup. It is exploitable when the 'manage_relationship' function is used with the 'on_lookup: :relate' option on a belongs_to relationship. Users are advised to update the library to the latest patched version.
Azərbaycanca: ash-proje layihəsinin 'ash' komponentində aşkar edilmiş bu boşluq, təcavüzkarın birbaşa adını bilmədiyi bir qeyd ilə saxta əlaqə qurmasına və bu əlaqəni tapmaq üçün istifadə olunan gizli dəyəri əldə etməsinə imkan verir. 'manage_relationship' funksiyası 'on_lookup: :relate' seçimi ilə istifadə edildikdə istismar olunur. istifadəçilərin kitabxananı ən son versiyaya yeniləməsi tövsiyə olunur.
FAQ2
Under what condition can CVE-2026-70395 in the ash-proje project be exploited?
This vulnerability is exploitable when the 'manage_relationship' function is used with the 'on_lookup: :relate' option on a 'belongs_to' relationship.
What is recommended for users to protect against CVE-2026-70395?
Users are advised to update the library to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.