CVE-2026-21618

Source
https://cve.org/CVERecord?id=CVE-2026-21618
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21618.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-21618
Aliases
Published
2026-01-19T15:15:50.693Z
Modified
2026-01-28T05:51:44.334718Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/hexpmweb/views/sharedauthorizationview.ex and program routines 'Elixir.HexpmWeb.SharedAuthorizationView':rendergrouped_scopes/3.

This issue affects hexpm: from 617e44c71f1dd9043870205f371d375c5c4d886d before c692438684ead90c3bcbfb9ccf4e63c768c668a8, from pkg:github/hexpm/hexpm@617e44c71f1dd9043870205f371d375c5c4d886d before pkg:github/hexpm/hexpm@c692438684ead90c3bcbfb9ccf4e63c768c668a8; hex.pm: from 2025-10-01 before 2026-01-19.

References

Affected packages

Git / github.com/hexpm/hexpm

Affected ranges

Type
GIT
Repo
https://github.com/hexpm/hexpm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21618.json"