PT-2026-22180 · Hexpm · Hexpm

Realcorvus

·

Publicado

2026-02-26

·

Atualizado

2026-02-27

·

CVE-2026-23939

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hexpm versions prior to 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0
Description A path traversal issue exists in hexpm’s Local Storage backend, impacting self-hosted deployments. The issue resides within the 'Elixir.Hexpm.Store.Local' module and affects the following program routines: get/3, put/4, delete/2, and delete/many/2, specifically within the file lib/hexpm/store/local.ex. This does not affect the hex.pm service itself. The issue allows relative path traversal.
Recommendations Update hexpm to version 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0 or later.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23939
GHSA-42MV-R64P-4869

Produtos afetados

Hexpm