PT-2026-96829 · Hexpm · Hex.Pm
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
hex.pm versions 2025-10-10 through 2026-09-21
Description
An insufficient session expiration issue in OAuth token issuance allows users whose organization membership or session has ended to continue reading private packages and documentation tarballs. This occurs because the
generate refresh token/4 function in lib/hexpm/oauth/jwt.ex signs refresh tokens with the same iss, aud, and scope claims as access tokens, including the repository:<org> scope. The CDN service serving private repositories authorizes access based on the scope claim after verifying the signature and time claims, without performing a database lookup. Consequently, the CDN cannot distinguish between access tokens and refresh tokens. While access tokens expire in 30 minutes, refresh tokens remain valid for 30 days, extending unauthorized read-only access to organizations the account belonged to at the time the token was granted.Recommendations
Update hex.pm to a version released on or after 2026-09-22.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hex.Pm