Am I affected?
This record states its affected versions in a form that can't be compared automatically.
Description
This vulnerability is associated with program files lib/hexpm/store/local.ex and program routines 'Elixir.Hexpm.Store.Local':get/3, 'Elixir.Hexpm.Store.Local':put/4, 'Elixir.Hexpm.Store.Local':delete/2, 'Elixir.Hexpm.Store.Local':delete_many/2.
This issue does NOT affect hex.pm the service. Only self-hosted deployments using the Local Storage backend are affected.
This issue affects hexpm: from 931ee0ed46fa89218e0400a4f6e6d15f96406050 before 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0.
Weaknesses & attack patterns
Weakness
CWE-22
·
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
in catalog →
MITRE ↗
Attack patterns
CAPEC-139
·
Relative Path Traversal
MITRE ↗
Affected — GitHub / hexpm/hexpm Repository ↗
modules · source files · routines
Workarounds
- Avoid the local file store backend in any exposed environment.
- Restrict network access to the registry when using the local backend.
- Production deployments should use object storage (e.g., S3-compatible backends) instead of the local filesystem store.
Configurations
References
GHSA-42mv-r64p-4869 ↗
vendor-advisory
EEF-CVE-2026-23939 ↗
related
Credits
CVSS breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N