Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Erlang Ecosystem Foundation

Erlang Ecosystem Foundation Vendor Cyber Rating & Cyber Score

erlef.org

The Erlang Ecosystem Foundation’s goal is to grow and support a diverse community around the Erlang and Elixir Ecosystem, encouraging the continued development of technologies and open source projects based on/around its runtime and languages.


EEF A.I CyberSecurity Scoring

EEF
Company Information
Website:https://erlef.org
Employees number:20
Number of followers:1,935
NAICS:5112
Industry Type:Software Development
Homepage:erlef.org
EEF Risk Score (AI oriented)
Between 700 and 749
logo
EEFSoftware Development
Updated:
31/08/2026
748/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
EEF Global Score (TPRM)
xxxx
logo
EEFSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

EEF
EEFModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
748Before Incident
AUGUST 2026
750Before Incident
Vulnerability
30 Aug 2026EEF
Erlang Ecosystem Foundation: AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields

Critical AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Data in Database Queries

748After Incident
CRITICAL-2
ERL1788171832
Critical AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Data in Database Queries On August 30, 2026, the Erlang Ecosystem Foundation’s CNA disclosed CVE-2026-77846, a JSONPath injection vulnerability in AshSqlite, a SQLite integration layer for the Ash Framework. The flaw allows attackers to traverse nested JSON structures and access sensitive or hidden fields in database records by manipulating untrusted input in field-selection requests. ### Key Details - Affected Versions: AshSqlite 0.1.2-rc.0 through 0.2.17 (patched in 0.2.18). - Root Cause: Unsafe construction of JSON paths, where attacker-controlled input (e.g., dots, brackets, or JSONPath symbols) could alter path interpretation, exposing nested data unintended for public access. - Exploitation Vector: Attackers exploit the flaw via public APIs, search filters, or field-selection endpoints that accept untrusted input. A proof-of-concept (PoC) demonstrated how a single malicious path segment could leak nested values (e.g., `{"private": {"secret": "api-key"}}`). - Impact: Systems processing untrusted input (e.g., public-facing applications) are at higher risk, while internal applications with trusted callers face lower exposure. The vulnerability does not involve SQL injection but abuses SQLite’s JSON path handling. ### Mitigation & Fixes - Patch: Upgrade to AshSqlite 0.2.18 or later, which replaces unsafe path joining with secure encoding, escaping backslashes/quotes, and separate handling of numeric array indexes. - Temporary Workarounds: Restrict dynamic field-selection input, audit logs for unusual JSONPath characters (e.g., dots, brackets), and review dependency locks for older versions. - Detection: Monitor for malformed input (e.g., unbalanced brackets) or SQLite JSON path errors, which may indicate exploitation attempts. The vulnerability underscores the risks of improper input validation in JSON path processing, particularly in applications handling sensitive data. Organizations using AshSqlite should prioritize upgrades and audits of affected systems.
INCIDENT DETAILS -
TYPE
JSONPath Injection Vulnerability
IMPACT
Data Compromised: Sensitive or hidden fields in database records (e.g., nested JSON data)Systems Affected: Systems using AshSqlite versions 0.1.2-rc.0 through 0.2.17Operational Impact: Potential exposure of unintended data in public-facing applications
DATA BREACH
Type Of Data Compromised: Nested JSON data (e.g., private fields, secrets, API keys)Sensitivity Of Data: High (sensitive or hidden fields)
JULY 2026
750Before Incident
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for EEF ?
?
What was EEF's A.I Rankiteo Cyber Score in August 2026 ?
?
What was EEF's A.I Rankiteo Cyber Score in July 2026 ?
?
What was EEF's A.I Rankiteo Cyber Score in June 2026 ?
?
What was EEF's A.I Rankiteo Cyber Score in May 2026 ?
?
What was EEF's A.I Rankiteo Cyber Score in April 2026 ?
?
What was EEF's A.I Rankiteo Cyber Score in March 2026 ?
?
What was EEF's A.I Rankiteo Cyber Score in February 2026 ?
?
What was EEF's A.I Rankiteo Cyber Score in January 2026 ?
?
What was EEF's A.I Rankiteo Cyber Score in December 2025 ?
?
What was EEF's A.I Rankiteo Cyber Score in November 2025 ?
?
What was EEF's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on EEF's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with EEF ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view EEF's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?