CVE-2026-75542
Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/08/2026
Última modificación:
24/08/2026
Descripción
*** Pendiente de traducción *** Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization&#39;s private packages.<br />
<br />
When an API key is exchanged for a token through the OAuth client_credentials grant, validate_scopes_against_key/2 in lib/hexpm_web/controllers/api/oauth_controller.ex admits a requested scope whenever the key carries the repositories permission and the scope string begins with repository:. The organization name is never resolved against the principal, and expand_repositories_scope/3 only rewrites the literal repositories scope, so an explicit repository: passes through untouched. Both CDN edges authorize repository access from the token claim without querying the database, so the minted token is read access to that organization&#39;s private packages until it expires.<br />
<br />
This issue affects hex.pm: from 2025-10-18 before 2026-08-24.
Impacto
Puntuación base 4.0
8.30
Gravedad 4.0
ALTA



