| ID | PPSA-202610-1 |
|---|---|
| Published | 2026-10-01 |
| Private Packagist Cloud | Affected. Fixed on 2026-10-01. |
| Private Packagist Self-Hosted (KOTS) | Affected <= 2.0.36. Fixed in 2.0.37. |
| Private Packagist Self-Hosted (Helm) | Affected <= 2.0.36. Fixed in 2.0.37. |
Summary
An attacker able to add or change package information in Private Packagist could have deleted the stored zip or tar archives of other organizations' package versions, and of public packages mirrored from repositories such as packagist.org, and had archives of their own stored in their place.
Who was affected
Private Packagist Cloud until the fix on October 1, 2026, and Private Packagist Self-Hosted installations running 2.0.36 or an earlier version. The attacker needed an account that can add a custom package or a mirrored third-party repository in any organization. To target a private package of another organization, the attacker had to know that organization's name, the package name and the version. To target the shared archive of a public mirrored package, only its public name and version were needed. On Self-Hosted, only organizations on the same installation could be targeted.
Impact
An attacker could have deleted the archive of a package version of another organization, or the shared archive of a public mirrored package version, and had an archive of their own stored in its place. Users installing that version through Private Packagist would then have downloaded the attacker's archive and used its code instead of the real package.
Private Packagist Cloud stores the archives of public mirrored packages once and shares them between all organizations. A replaced archive of a public mirrored package could therefore have affected every organization that installed that version through Private Packagist Cloud, not only a single target.
Deleting an archive without replacing it had little effect, because Private Packagist builds a missing archive again the next time the version is installed. Installs from source, for example with composer install --prefer-source, did not use the archives and were not affected. The attacker could not read the archives or the code of other organizations' packages, and could not change other organizations' package information, credentials, members or settings.
What we did
On September 30, 2026, we started rejecting archive download requests with a version that would point outside the package's own archive location. On October 1, 2026, we also started rejecting versions, archive types and mirrored repository URLs that would point outside the package's own archive location, so no archive is built, served or deleted for them.
We found this vulnerability during an internal investigation, after one of our internal alerts fired in related code, and fixed it right away.
To the best of our knowledge, this vulnerability was not exploited. We reviewed the audit logs, the background job history and the storage access logs of Private Packagist Cloud going back years, looking in particular for archives of public mirrored packages that were removed or replaced. We found none. Before this investigation, we had also never received the kind of alert that exploiting this vulnerability would almost certainly have triggered.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 2.0.37 or any later version. We recommend upgrading to the latest release. Afterwards, run this command to check your installation for package versions, mirrored repositories, audit log entries and archive jobs that match this vulnerability. It prints one line for each match, and otherwise "No compromising package versions found", "No compromising mirrored repositories found", "No compromising audit log entries found" and "No compromising archive jobs found". Archive jobs are only kept for a limited time, so the command also prints the date of the oldest archive job it could check. If it reports any match, contact us at contact@packagist.com.
kubectl exec $(kubectl get pods --field-selector=status.phase=Running --no-headers -o custom-columns=":metadata.name"|grep worker-) -- /bin/sh -c "/srv/manager/bin/console packagist:audit --vulnerability dist-path-traversal" - Private Packagist Cloud: No action is required.
Start Free Trial
Login to create an organization and start your free trial!