Browse all 10 CVE security advisories affecting hexpm. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Hexpm serves as the package manager for the Elixir language ecosystem, enabling developers to distribute and manage dependencies. Historically, vulnerabilities in hexpm-related packages have commonly included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insecure input validation or improper access controls. While no major security incidents have been widely documented, the 7 CVEs on record highlight potential risks in dependency integrity and package verification. The platform's security relies on community vigilance and hexpm's infrastructure safeguards, though the distributed nature of package maintenance remains a challenge for consistent security oversight across the ecosystem.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-86698 | Refresh tokens accepted as private repository credentials at the CDN — hexpm CWE-613 | 2.3 | Low | 2026-09-22 |
| CVE-2026-75554 | Explicit organization scopes survive token refresh after membership ends — hexpm CWE-613 | 2.3 | Low | 2026-08-24 |
| CVE-2026-75542 | OAuth token exchange grants repository scopes for organizations the principal cannot access — hexpm CWE-863 | 8.3 | High | 2026-08-24 |
| CVE-2026-23940 | Denial of Service via Oversized Package Upload — hexpm CWE-400 | 7.1 | High | 2026-03-13 |
| CVE-2026-21622 | Password Reset Tokens Do Not Expire — hexpm CWE-613 | 8.1 | - | 2026-03-05 |
| CVE-2026-21621 | Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access — hexpm CWE-863 | 8.8 | - | 2026-03-05 |
| CVE-2026-23939 | Path Traversal in Local File Store Backend — hexpm CWE-22 | 6.9 | Medium | 2026-02-26 |
| CVE-2026-21618 | Cross-site scripting (XSS) in OAuth Device Authorization screen — hexpm CWE-79 | 8.5 | High | 2026-01-19 |
This page lists every published CVE security advisory associated with hexpm. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.