VYPR
Medium severity6.1OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026

CVE-2026-59946

CVE-2026-59946

Description

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
composer/composerPackagist
>= 2.3.0, < 2.10.22.10.2
composer/composerPackagist
>= 1.0.0, < 2.2.292.2.29

Affected products

5

Patches

Vulnerability mechanics

References

7

News mentions

1