PT-2026-22180 · Hexpm · Hexpm

Realcorvus

·

Published

2026-02-26

·

Updated

2026-02-27

·

CVE-2026-23939

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hexpm versions prior to 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0
Description A path traversal issue exists in hexpm’s Local Storage backend, impacting self-hosted deployments. The issue resides within the 'Elixir.Hexpm.Store.Local' module and affects the following program routines: get/3, put/4, delete/2, and delete/many/2, specifically within the file lib/hexpm/store/local.ex. This does not affect the hex.pm service itself. The issue allows relative path traversal.
Recommendations Update hexpm to version 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23939
GHSA-42MV-R64P-4869

Affected Products

Hexpm