VYPR
High severity7.0OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026

CVE-2026-59948

CVE-2026-59948

Description

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
composer/composerPackagist
>= 2.3.0, < 2.10.22.10.2
composer/composerPackagist
>= 1.0.0, < 2.2.292.2.29

Affected products

5

Patches

Vulnerability mechanics

References

7

News mentions

1