Path Traversal in Local File Store Backend
Published Feb 26, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.43%
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module) allows Relative Path Traversal. This vulnerability is associated with program files lib/hexpm/store/local.ex and program routines 'Elixir.Hexpm.Store.Local':get/3, 'Elixir.Hexpm.Store.Local':put/4, 'Elixir.Hexpm.Store.Local':delete/2, 'Elixir.Hexpm.Store.Local':delete_many/2.
This issue does NOT affect hex.pm the service. Only self-hosted deployments using the Local Storage backend are affected.
This issue affects hexpm: from 931ee0ed46fa89218e0400a4f6e6d15f96406050 before 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0.
Affected products
-
- Version StatusaffectedConstraints
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
* Avoid the local file store backend in any exposed environment. * Restrict network access to the registry when using the local backend. * Production deployments should use object storage (e.g., S3-compatible backends) instead of the local filesystem store.
References (5)
- https://cna.erlef.org/cves/CVE-2026-23939.html related
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-8886 Advisory
- https://github.com/hexpm/hexpm/commit/5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0 patch
- https://github.com/hexpm/hexpm/security/advisories/GHSA-42mv-r64p-4869 vendor-advisoryrelatedMitigationVendor Advisory
- https://osv.dev/vulnerability/EEF-CVE-2026-23939 related
| Link | Providers | Tags |
|---|---|---|
| https://cna.erlef.org/cves/CVE-2026-23939.html | related | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-8886 | Advisory | |
| https://github.com/hexpm/hexpm/commit/5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0 | patch | |
| https://github.com/hexpm/hexpm/security/advisories/GHSA-42mv-r64p-4869 | vendor-advisoryrelatedMitigationVendor Advisory | |
| https://osv.dev/vulnerability/EEF-CVE-2026-23939 | related |
Change history (0)
No recorded changes yet.