---
id: CVE-2026-21618
title: >-
  Improper Neutralization of Input During Web Page Generation (XSS or
  'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm
  ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site
  Scripting (XSS)
summary: >-
  Improper Neutralization of Input During Web Page Generation (XSS or
  'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm
  ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site
  Scripting (XSS). This vulnerability is a…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: hex
product: hexpm
affected:
  - 'hexpm >= 2025-10-01, < 2026-01-19'
patched:
  - hexpm 2026-01-19
published: '2026-01-19'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21618'
references:
  - url: 'https://cna.erlef.org/cves/CVE-2026-21618.html'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: >-
      https://github.com/hexpm/hexpm/commit/c692438684ead90c3bcbfb9ccf4e63c768c668a8
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: 'https://github.com/hexpm/hexpm/security/advisories/GHSA-6cw9-5gg4-rhpj'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: 'https://osv.dev/vulnerability/EEF-CVE-2026-21618'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
tags:
  - nvd
epss: 0.00255
epssPercentile: 0.153
ingestedAt: '2026-07-24T15:30:58.071Z'
---

## Overview

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/hexpm_web/views/shared_authorization_view.ex and program routines 'Elixir.HexpmWeb.SharedAuthorizationView':render_grouped_scopes/3.

This issue affects hexpm: from 617e44c71f1dd9043870205f371d375c5c4d886d before c692438684ead90c3bcbfb9ccf4e63c768c668a8; hex.pm: from 2025-10-01 before 2026-01-19.

## Affected

- `hexpm >= 2025-10-01, < 2026-01-19`

## Remediation

Upgrade past the affected range:

- `hexpm 2026-01-19`
