CVE-2026-75554: Hexpm Oauth Unvalidated Organization Scopes

OAuth token generation expands repository scopes without filtering unaffiliated organization scopes against current user memberships, allowing revoked organization members to maintain access via token refresh grants.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Elixir
greprules fetch cve-2026-75554-hexpm-oauth-unvalidated-organization-scopes --engine opengrep

Description

OAuth token generation expands repository scopes without filtering unaffiliated organization scopes against current user memberships, allowing revoked organization members to maintain access via token refresh grants.