EEF-CVE-2026-21618

Source
https://cna.erlef.org/osv/EEF-CVE-2026-21618.html
Import Source
https://cna.erlef.org/osv/EEF-CVE-2026-21618.json
JSON Data
https://api.osv.dev/v1/vulns/EEF-CVE-2026-21618
Aliases
Published
2026-01-19T14:22:46.770Z
Modified
2026-01-21T07:00:48.335602Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Cross-site scripting (XSS) in OAuth Device Authorization screen
Details

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/hexpmweb/views/sharedauthorizationview.ex and program routines 'Elixir.HexpmWeb.SharedAuthorizationView':rendergrouped_scopes/3.

This issue affects hexpm: from 617e44c71f1dd9043870205f371d375c5c4d886d before c692438684ead90c3bcbfb9ccf4e63c768c668a8, from pkg:github/hexpm/hexpm@617e44c71f1dd9043870205f371d375c5c4d886d before pkg:github/hexpm/hexpm@c692438684ead90c3bcbfb9ccf4e63c768c668a8; hex.pm: from 2025-10-01 before 2026-01-19.

Database specific
{
    "cpe_ids": [
        "cpe:2.3:a:hexpm:hexpm:*:*:*:*:*:*:*:*"
    ],
    "cwe_ids": [
        "CWE-79"
    ],
    "capec_ids": [
        "CAPEC-63"
    ]
}
References
Credits
    • Joud Zakharia / zentrust partners GmbH - FINDER
    • Jonatan Männchen / EEF - REMEDIATION_DEVELOPER
    • Eric Meadows-Jönsson / Hex.pm - REMEDIATION_REVIEWER

Affected packages

Git / github.com/hexpm/hexpm.git

Affected ranges

Type
GIT
Repo
https://github.com/hexpm/hexpm.git
Events

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21618.json"