PatchSiren

Hex CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Hex CVE published 2026-01-19

CVE-2026-21618

A Cross-Site Scripting (XSS) vulnerability was found in Hexpm, affecting versions from 2025-10-01 before 2026-01-19. The issue is caused by improper neutralization of input during web page generation in the 'Elixir.HexpmWeb.SharedAuthorizationView' modules. This vulnerability has a CVSS score of 8.5 and is classified as HIGH. The vulnerability is located in the 'Elixir.HexpmWeb.SharedAuthorizationView' mo [truncated]