Previous Composer authentication token stayed valid after regenerating it

PPSA-202605-2


Summary

After a user regenerated their personal Composer authentication token, the previous token kept working for Composer downloads for up to 14 days.

Who was affected

Users who regenerated their personal Composer authentication token on the Composer Auth page of their user profile, on Private Packagist Cloud until the fix on May 26, 2026, and on Private Packagist Self-Hosted installations running a version before 2.0.33.

Impact

If a user regenerated their personal Composer authentication token because it had been exposed, an attacker holding the previous token could still have used it for up to 14 days after the regeneration to download the packages the user had access to. The previous token only worked for Composer downloads. It could not be used to log in or to change anything.

What we did

Regenerating a personal Composer authentication token now immediately invalidates the previous token. On Private Packagist Cloud, we revoked all previously regenerated tokens that were still accepted at the time of the fix. On Self-Hosted, upgrading to 2.0.33 revokes them as part of the upgrade.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.33 or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!