Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password reset tokens generated via the "Reset your password" flow do not expire. When a user requests a password reset, Hex sends an email containing a reset link with a token. This token remains valid indefinitely until used. There is no time-based expiration enforced. If a user's historical emails are exposed through a data breach (e.g., a leaked mailbox archive), any unused password reset email contained in that dataset could be used by an attacker to reset the victim's password. The attacker does not need current access to the victim's email account, only access to a previously leaked copy of the reset email. This vulnerability is associated with program files lib/hexpm/accounts/password_reset.ex and program routines 'Elixir.Hexpm.Accounts.PasswordReset':can_reset?/3. This issue affects hexpm: from 617e44c71f1dd9043870205f371d375c5c4d886d before bb0e42091995945deef10556f58d046a52eb7884.
When a user initiates a password reset procedure, the Hex service sends an email with a reset token embedded in a link. This token has no time-based expiration mechanism — it remains valid indefinitely until it is used. The function responsible for token verification ('Elixir.Hexpm.Accounts.PasswordReset':can_reset?/3) does not check its issuance date. If the victim's email archive leaks (for example, due to a security breach at another service), an attacker can use any unused reset token contained in that archive and change the password to the Hex account.
An attacker can take over a user account on the Hex platform (Account Takeover), gaining the ability to publish, modify, or delete Elixir packages belonging to the victim, which can lead to further compromise of software supply chain integrity.
Update hexpm to a version containing commit bb0e42091995945deef10556f58d046a52eb7884, which introduces time-based expiration for password reset tokens. Details available in vendor references: https://github.com/hexpm/hexpm/commit/bb0e42091995945deef10556f58d046a52eb7884 and https://github.com/hexpm/hexpm/security/advisories/GHSA-6r94-pvwf-mxqm
Application hexpm (hexpm/hexpm) — commits from 617e44c71f1dd9043870205f371d375c5c4d886d to (not including) bb0e42091995945deef10556f58d046a52eb7884
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHex Hexpm
APPHex2025-10-01 – 2026-03-05 (excl.)
Related vulnerabilities
Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing a...
Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allo...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in h...
Luka path traversal w module 'Elixir.Hexpm.Store.Local' projektu hexpm/hexpm pozwala na względny path traversa...
Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows ...