PT-2026-22180 · Hexpm · Hexpm
Realcorvus
·
Published
2026-02-26
·
Updated
2026-02-27
·
CVE-2026-23939
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
hexpm versions prior to 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0
Description
A path traversal issue exists in hexpm’s Local Storage backend, impacting self-hosted deployments. The issue resides within the 'Elixir.Hexpm.Store.Local' module and affects the following program routines:
get/3, put/4, delete/2, and delete/many/2, specifically within the file lib/hexpm/store/local.ex. This does not affect the hex.pm service itself. The issue allows relative path traversal.Recommendations
Update hexpm to version 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hexpm