Authorization Bypass Through User-Controlled Key vulnerability in ash-project ashphoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, turning the returned rows into a boolean oracle over private related data.
AshPhoenix.FilterForm resolved every relationship hop in the user-supplied path with Ash.Resource.Info.related/2, which traverses private relationships, and only checked the terminal field for publicity. parsepathandfield/2 also rewrote a field naming a relationship into an extra path segment, so field=someprivaterel was accepted too. Both path and field come straight from form params, and the resulting ref went to Ash.Query.dofilter/2 without the public-only enforcement of Ash.Filter.parseinput/2. The fix resolves each hop with Ash.Resource.Info.publicrelationship/2, rejecting the first non-public hop, and requires the terminal field to be public.
This issue affects ashphoenix: from 0.6.0-rc.1 before 2.3.25.