PT-2026-22108 · Packistry · Packistry

Maantje

·

Publicado

2026-02-26

·

Atualizado

2026-02-26

·

CVE-2026-27968

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Packistry versions prior to 0.13.0
Description Packistry is a self-hosted Composer repository for PHP package distribution. Prior to version 0.13.0, the RepositoryAwareController::authorize() function did not enforce token expiration, allowing expired deploy tokens with the correct ability to access repository endpoints, such as Composer metadata and download APIs. The fix in version 0.13.0 adds an explicit expiration check to the authorize() function, and tests now verify that expired deploy tokens are rejected.
Recommendations Update to version 0.13.0 or later.

Exploit

Correção

Insufficient Session Expiration

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27968
GHSA-4R9M-JP53-VGMW

Produtos afetados

Packistry