On 24 August 2026 we found and fixed two vulnerabilities in how hex.pm issues OAuth tokens. Both could give an account read access to private packages of an organization it was not entitled to. Neither was being exploited when we found them: no active token carried a scope for an organization its holder could not access.
Private package authorization vulnerabilities
calendar_today
September 1, 2026
domain
hex-pm