CVE-2026-23939

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
26/02/2026
Last modified:
27/02/2026

Description

Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) vulnerability in hexpm hexpm/hexpm (&amp;#39;Elixir.Hexpm.Store.Local&amp;#39; module) allows Relative Path Traversal. This vulnerability is associated with program files lib/hexpm/store/local.ex and program routines &amp;#39;Elixir.Hexpm.Store.Local&amp;#39;:get/3, &amp;#39;Elixir.Hexpm.Store.Local&amp;#39;:put/4, &amp;#39;Elixir.Hexpm.Store.Local&amp;#39;:delete/2, &amp;#39;Elixir.Hexpm.Store.Local&amp;#39;:delete_many/2.<br /> <br /> This issue does NOT affect hex.pm the service. Only self-hosted deployments using the Local Storage backend are affected.<br /> <br /> This issue affects hexpm: from 931ee0ed46fa89218e0400a4f6e6d15f96406050 before 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0.