Suborganization admins could add parent organization packages they had no access to

PPSA-202609-1


Summary

A malicious suborganization admin could have added private packages, notification channels and mirrored third-party repositories of the parent organization to their suborganization, even if they had no access to them in the parent organization.

Who was affected

Organizations with suborganizations whose admins do not have access to all packages, notification channels or mirrored third-party repositories of the parent organization, on Private Packagist Cloud until the fix on September 30, 2026, and on Private Packagist Self-Hosted installations running 2.0.36 or an earlier version. The attacker had to be an admin of one of the organization's suborganizations, and had to know or guess the internal identifier of each item in the parent organization. The forms in Private Packagist only offered items the admin had access to, so the attacker also had to send modified requests instead of using them. Organizations without suborganizations were not affected, and neither were items that a suborganization admin already had access to in the parent organization.

Impact

A malicious suborganization admin could have copied private packages of the parent organization into their suborganization, then installed them and read their source code. They could also have added a notification channel of the parent organization to their suborganization and added subscriptions to it, without being able to read the channel's details, and made a mirrored third-party repository of the parent organization available in their suborganization.

The attacker could not change or delete the packages, notification channels or mirrored third-party repositories of the parent organization, and could not reach organizations other than the parent of their own suborganization.

What we did

On September 30, 2026, we changed how packages, notification channels and mirrored third-party repositories are added to a suborganization: Private Packagist now checks the admin's access in the parent organization and rejects anything the admin may not add.

We reviewed the audit logs of Private Packagist Cloud and could not find a case where this vulnerability was exploited.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.37 or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.
  • If you do not fully trust all of your suborganization admins, review the packages, notification channels and mirrored third-party repositories in each of their suborganizations.

Credits

Thanks to TruongLV1 from FPT NightWolf for reporting this issue.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!