VYPR
Medium severity4.7OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026

CVE-2026-59947

CVE-2026-59947

Description

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
composer/composerPackagist
>= 2.3.0, < 2.10.22.10.2
composer/composerPackagist
>= 1.0.0, < 2.2.292.2.29

Affected products

5

Patches

Vulnerability mechanics

References

7

News mentions

1