CVE-2026-75554: Hexpm Oauth Unvalidated Organization Scopescve-2026-75554-hexpm-oauth-unvalidated-organization-scopes
OAuth token generation expands repository scopes without filtering unaffiliated organization scopes against current user memberships, allowing revoked organization members to maintain access via token refresh grants.