Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-81322

Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-200 Revelación de información
Fecha de publicación:
30/08/2026
Última modificación:
30/08/2026

Descripción

*** Pendiente de traducción *** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.<br /> <br /> AshCloak.Transformers.SetUpEncryption removes each cloaked attribute from the action&amp;#39;s accept list and adds an action argument that carries the plaintext into the encryption change. That argument is built with sensitive?: attr.sensitive?, inheriting the flag from the source attribute, so a cloaked attribute declared without sensitive? true produces a non-sensitive argument. It is the only place the cleartext value lives, and the one place Ash will not redact: it appears verbatim in inspect(changeset), Ash.Error.Invalid and validation error messages, telemetry, :sys dumps, and error-tracker payloads. The generated encrypted attribute and decrypt calculation are already hardcoded sensitive.<br /> <br /> This issue affects ash_cloak: from 0.1.0 before 0.4.0.