CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer
Vulnerability ID: CVE-2026-59944
CVSS Score: 6.1
Published: 2026-10-02
CVE-2026-59944 is a path traversal and link-following vulnerability in Composer, the PHP dependency manager. This flaw allows malicious or compromised packages to bypass previous path-hardening protections and perform arbitrary filesystem operations outside of their designated installation directory, leading to unauthorized permission modifications or execution proxy creations.
TL;DR
A vulnerability in Composer allows malicious dependencies or manipulated installed.json files to bypass binary path validation. This enables attackers to execute chmod operations or create execution proxies targeting sensitive files outside the package installation directory.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22, CWE-59
- Attack Vector: Local
- CVSS v3.1 Score: 6.1 (Medium)
- EPSS Score / Percentile: 0.00322 / 22.99%
- Impact: Filesystem Permission Modification, Execution Proxying
- Exploit Status: Proof of Concept
- CISA KEV Status: Not Listed
Affected Systems
- Composer (PHP dependency manager)
Mitigation Strategies
- Upgrade Composer to patched versions (2.2.30 or 2.10.3)
- Enforce least-privilege principles for execution context
- Audit existing deployment scripts and dependency directories for unauthorized symlinks
Remediation Steps:
- Run 'composer self-update' to obtain the latest security patches.
- If running legacy environments, pin to the 2.2 branch via 'composer self-update --2.2'.
- Utilize 'find vendor/ -type l -lname "../*"' to scan dependencies for external symbolic links.
References
Read the full report for CVE-2026-59944 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)