Back

MEDIUM

Path Traversal in Local File Store Backend

Published Feb 26, 2026

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module) allows Relative Path Traversal. This vulnerability is associated with program files lib/hexpm/store/local.ex and program routines 'Elixir.Hexpm.Store.Local':get/3, 'Elixir.Hexpm.Store.Local':put/4, 'Elixir.Hexpm.Store.Local':delete/2, 'Elixir.Hexpm.Store.Local':delete_many/2.

This issue does NOT affect hex.pm the service. Only self-hosted deployments using the Local Storage backend are affected.

This issue affects hexpm: from 931ee0ed46fa89218e0400a4f6e6d15f96406050 before 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0.

Affected products

Remediation

Vendor solution

* Avoid the local file store backend in any exposed environment. * Restrict network access to the registry when using the local backend. * Production deployments should use object storage (e.g., S3-compatible backends) instead of the local filesystem store.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner EEF
Published Feb 26, 2026
Updated Sep 16, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated Feb 26, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner EEF
Published Feb 26, 2026
Updated Sep 16, 2026
Exploited since n/a
EUVD-2026-8886