CVE-2026-23939
Severity CVSS v4.0:
MEDIUM
Type:
CWE-22
Path Traversal
Publication date:
26/02/2026
Last modified:
06/04/2026
Description
Improper Limitation of a Pathname to a Restricted Directory (&#39;Path Traversal&#39;) vulnerability in hexpm hexpm/hexpm (&#39;Elixir.Hexpm.Store.Local&#39; module) allows Relative Path Traversal. This vulnerability is associated with program files lib/hexpm/store/local.ex and program routines &#39;Elixir.Hexpm.Store.Local&#39;:get/3, &#39;Elixir.Hexpm.Store.Local&#39;:put/4, &#39;Elixir.Hexpm.Store.Local&#39;:delete/2, &#39;Elixir.Hexpm.Store.Local&#39;:delete_many/2.<br />
<br />
This issue does NOT affect hex.pm the service. Only self-hosted deployments using the Local Storage backend are affected.<br />
<br />
This issue affects hexpm: from 931ee0ed46fa89218e0400a4f6e6d15f96406050 before 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hex:hexpm:*:*:*:*:*:*:*:* | 2014-09-29 (including) | 2026-02-26 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



