CVE-2026-23939 | hexpm lib/hexpm/store/local.ex delete_many path traversal
A vulnerability, which was classified as critical, was found in hexpm. This affects the function delete_many in the library lib/hexpm/store/local.ex. The manipulation results in path traversal.
This vulnerability is reported as CVE-2026-23939. The attack can be launched remotely. No exploit exists.
A patch should be applied to remediate this issue.