{"id":"CVE-2025-48044","title":"Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.\n\nThis issue affects ash: from 3.6.3 before 3.7.1.","summary":"Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.\n\nThis issue affects ash: from 3.6.3 before 3.7.1.","severity":"high","cvss":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-863"],"vendor":"ash-project","product":"ash","affected":["ash >= 3.6.3 < 3.7.1","ash-project/ash >= 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 < 8b83efa225f657bfc3656ad8ee8485f9b2de923d"],"published":"2025-10-17","updated":"2026-09-22","sourceUpdated":"2026-09-22T10:17:08.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-48044","references":[{"url":"https://cna.erlef.org/cves/CVE-2025-48044.html","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ash-project/ash/commit/79749c2685ea031ebb2de8cf60cc5edced6a8dd0","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ash-project/ash/commit/8b83efa225f657bfc3656ad8ee8485f9b2de923d","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ash-project/ash/security/advisories/GHSA-pcxq-fjp3-r752","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2025-48044","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ash-project/ash/security/advisories/GHSA-pcxq-fjp3-r752","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org"],"epss":0.00663,"epssPercentile":0.49912,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2025-10-20T18:42:50.579615Z"},"cvssSource":"cna","ingestedAt":"2026-07-24T15:30:58.005Z","slug":"CVE-2025-48044","body":"## Overview\n\nIncorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.\n\nThis issue affects ash: from 3.6.3 before 3.7.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208998,"id":"CVE-2025-48044","ts":1790071338393,"field":"cvss","old":null,"new":"8.6"},{"seq":208997,"id":"CVE-2025-48044","ts":1790071338393,"field":"severity","old":"none","new":"high"}]}