Answer in brief
CVE-2025-48042 records a Unknown severity vulnerability in Before action hooks may execute in certain scenarios despite a request being forbidden. The current sources do not mark it as known exploited. The current feed maps ash-project/ash (generic), ash-project/ash (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ash-project/ash (generic), ash-project/ash (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ash-project/ashgeneric | >=0.1.1 <3.5.39 | 3.5.39 |
| ash-project/ashgeneric | >=4c41344126b0aba09ec3085517000f8aefec299e <5d1b6a5d00771fd468a509778637527b5218be9a | 5d1b6a5d00771fd468a509778637527b5218be9a |
Published upstream
Sep 7, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 22, 2026
Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.
Quoted source text, attributed separately from HOL analysis.