Description
Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segments only during dependency resolution, while the symlink and installed-metadata paths described by the advisory skip that validation. A package can ship an in-package binary symlink that resolves outside its installation directory, or attacker-influenced vendor/composer/installed.json metadata can provide an escaping binary path during a reinstall or regeneration of missing vendor/bin entries. The installed-metadata path is reachable only when the vendor directory was not populated by the same validated install run, such as when it is restored from an untrusted cache, copied from an earlier build stage, carried over from an older Composer run, or writable by a lower-trust build step. Composer can follow the path, change the external target's permissions to make it world-readable and executable, and create a runnable vendor/bin proxy to that external file. The issue does not directly read or transmit data and does not by itself provide remote code execution. This issue is fixed in versions 2.2.30 and 2.10.3.
Published: 2026-09-16
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential local code execution via vendor/bin proxy
Action: Immediate Patch
AI Analysis

Impact

Composer, a PHP dependency manager, allowed packages to bypass binary-path hardening from versions 1.0 through 2.2.30 and from 2.3.0 through 2.10.3. The vulnerability occurs because composer validates only literal parent‑directory segments during dependency resolution; a malicious package can supply a symlinked binary that points outside its installation directory, or an attacker‑influenced vendor/composer/installed.json entry can provide an escaping path during reinstall or regeneration of missing vendor/bin entries. Composer will follow such a path, adjust permissions to make the target world‑readable and executable, and create a runnable vendor/bin proxy. Although the flaw does not directly read or transmit data, it enables execution of arbitrary code within the context of the composer run, potentially allowing local privilege escalation or code execution. }

Affected Systems

The affected product is Composer (composer:composer). Vulnerable releases include all Composer versions from 1.0 up to and including 2.2.30, as well as 2.3.0 up to and including 2.10.3. Versions 2.2.30 and 2.10.3 have the fix.

Risk and Exploitability

With a CVSS score of 6.1 and an EPSS score below 1%, this vulnerability poses a moderate risk. It has not entered the CISA KEV catalog. Exploitation requires an attacker who can influence the dependency list or the installed.json metadata during a composer install or update – for example, a build system that fetches packages from an untrusted source or restores a vendor directory from a cache. The attack vector is local; the attacker must have the ability to supply a malicious package or modify the composer metadata. Once executed, the attacker can gain the rights of the user running composer, which may lead to code execution or privilege escalation within that environment.

Generated by OpenCVE AI on September 18, 2026 at 01:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Composer to version 2.10.3 or newer, or to 2.2.30 for older major releases.
  • Configure your build pipeline to use only trusted Composer caches or reinstall the vendor directory from a secure source on each run.
  • Avoid running composer as an elevated user and limit write access to the vendor/composer/installed.json file to prevent tampering by lower‑trust processes.

Generated by OpenCVE AI on September 18, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-96h3-5x6v-m776 Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Getcomposer
Getcomposer composer
Vendors & Products Getcomposer
Getcomposer composer

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segments only during dependency resolution, while the symlink and installed-metadata paths described by the advisory skip that validation. A package can ship an in-package binary symlink that resolves outside its installation directory, or attacker-influenced vendor/composer/installed.json metadata can provide an escaping binary path during a reinstall or regeneration of missing vendor/bin entries. The installed-metadata path is reachable only when the vendor directory was not populated by the same validated install run, such as when it is restored from an untrusted cache, copied from an earlier build stage, carried over from an older Composer run, or writable by a lower-trust build step. Composer can follow the path, change the external target's permissions to make it world-readable and executable, and create a runnable vendor/bin proxy to that external file. The issue does not directly read or transmit data and does not by itself provide remote code execution. This issue is fixed in versions 2.2.30 and 2.10.3.
Title Composer: CVE-2026-59946 fix bypass via symlinked package bin path
Weaknesses CWE-22
CWE-59
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Getcomposer Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:29:39.824Z

Reserved: 2026-07-07T18:49:15.607Z

Link: CVE-2026-59944

cve-icon Vulnrichment

Updated: 2026-09-16T17:29:22.350Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:17:28.590

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-59944

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T16:09:43Z

Links: CVE-2026-59944 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:30Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')