DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-59944: CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

Vulnerability ID: CVE-2026-59944
CVSS Score: 6.1
Published: 2026-10-02

CVE-2026-59944 is a path traversal and link-following vulnerability in Composer, the PHP dependency manager. This flaw allows malicious or compromised packages to bypass previous path-hardening protections and perform arbitrary filesystem operations outside of their designated installation directory, leading to unauthorized permission modifications or execution proxy creations.

TL;DR

A vulnerability in Composer allows malicious dependencies or manipulated installed.json files to bypass binary path validation. This enables attackers to execute chmod operations or create execution proxies targeting sensitive files outside the package installation directory.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-22, CWE-59
  • Attack Vector: Local
  • CVSS v3.1 Score: 6.1 (Medium)
  • EPSS Score / Percentile: 0.00322 / 22.99%
  • Impact: Filesystem Permission Modification, Execution Proxying
  • Exploit Status: Proof of Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • Composer (PHP dependency manager)

Mitigation Strategies

  • Upgrade Composer to patched versions (2.2.30 or 2.10.3)
  • Enforce least-privilege principles for execution context
  • Audit existing deployment scripts and dependency directories for unauthorized symlinks

Remediation Steps:

  1. Run 'composer self-update' to obtain the latest security patches.
  2. If running legacy environments, pin to the 2.2 branch via 'composer self-update --2.2'.
  3. Utilize 'find vendor/ -type l -lname "../*"' to scan dependencies for external symbolic links.

References


Read the full report for CVE-2026-59944 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)