Insufficient Session Expiration in hexpm by Hexpm
CVE-2026-75554
2.3LOW
What is CVE-2026-75554?
The insufficient session expiration vulnerability in hexpm allows users who have been removed from an organization to continue accessing private packages. This occurs because the OAuth token refresh process does not properly update access rights. When a token is refreshed, it retains permissions associated with the user’s previous membership, permitting continued access for up to 30 days, which presents a significant security risk.
Affected Version(s)
hexpm 2025-10-10 < 2026-08-24
hexpm 650faa03af511e74c1b3b49ec12d35666b6984c4 < 50cffd206490c49c92d7b63c8505949682abedb0
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Eric Meadows-Jönsson
Eric Meadows-Jönsson
Jonatan Männchen / EEF
