| ID | PPSA-202605-2 |
|---|---|
| Published | 2026-05-26 |
| Private Packagist Cloud | Affected. Fixed on 2026-05-26. |
| Private Packagist Self-Hosted (KOTS) | Affected < 2.0.33. Fixed in 2.0.33. |
| Private Packagist Self-Hosted (Helm) | Affected < 2.0.33. Fixed in 2.0.33. |
Summary
After a user regenerated their personal Composer authentication token, the previous token kept working for Composer downloads for up to 14 days.
Who was affected
Users who regenerated their personal Composer authentication token on the Composer Auth page of their user profile, on Private Packagist Cloud until the fix on May 26, 2026, and on Private Packagist Self-Hosted installations running a version before 2.0.33.
Impact
If a user regenerated their personal Composer authentication token because it had been exposed, an attacker holding the previous token could still have used it for up to 14 days after the regeneration to download the packages the user had access to. The previous token only worked for Composer downloads. It could not be used to log in or to change anything.
What we did
Regenerating a personal Composer authentication token now immediately invalidates the previous token. On Private Packagist Cloud, we revoked all previously regenerated tokens that were still accepted at the time of the fix. On Self-Hosted, upgrading to 2.0.33 revokes them as part of the upgrade.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 2.0.33 or any later version. We recommend upgrading to the latest release.
- Private Packagist Cloud: No action is required.
Start Free Trial
Login to create an organization and start your free trial!