Medium severity4.3NVD Advisory· Published Feb 26, 2026· Updated Jun 17, 2026
CVE-2026-27968
CVE-2026-27968
Description
Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but did not enforce token expiration. As a result, an expired deploy token with the correct ability could still access repository endpoints (e.g., Composer metadata/download APIs). The fix in version 0.13.0 adds an explicit expiration check, and tests now test expired deploy tokens to ensure they are rejected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/packistry/packistry/commit/7740b48f0f4ecbe63099fb056c8a146180f8b283nvdPatch
- github.com/packistry/packistry/pull/276nvdIssue TrackingPatch
- github.com/packistry/packistry/security/advisories/GHSA-4r9m-jp53-vgmwnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.