Impact
Composer, a PHP dependency manager, allowed packages to bypass binary-path hardening from versions 1.0 through 2.2.30 and from 2.3.0 through 2.10.3. The vulnerability occurs because composer validates only literal parent‑directory segments during dependency resolution; a malicious package can supply a symlinked binary that points outside its installation directory, or an attacker‑influenced vendor/composer/installed.json entry can provide an escaping path during reinstall or regeneration of missing vendor/bin entries. Composer will follow such a path, adjust permissions to make the target world‑readable and executable, and create a runnable vendor/bin proxy. Although the flaw does not directly read or transmit data, it enables execution of arbitrary code within the context of the composer run, potentially allowing local privilege escalation or code execution. }
Affected Systems
The affected product is Composer (composer:composer). Vulnerable releases include all Composer versions from 1.0 up to and including 2.2.30, as well as 2.3.0 up to and including 2.10.3. Versions 2.2.30 and 2.10.3 have the fix.
Risk and Exploitability
With a CVSS score of 6.1 and an EPSS score below 1%, this vulnerability poses a moderate risk. It has not entered the CISA KEV catalog. Exploitation requires an attacker who can influence the dependency list or the installed.json metadata during a composer install or update – for example, a build system that fetches packages from an untrusted source or restores a vendor directory from a cache. The attack vector is local; the attacker must have the ability to supply a malicious package or modify the composer metadata. Once executed, the attacker can gain the rights of the user running composer, which may lead to code execution or privilege escalation within that environment.
OpenCVE Enrichment
Github GHSA