Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59948

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 7
EPSS Низкий

Описание

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.

EPSS

Процентиль: 3%
0.00132
Низкий

7 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7
ubuntu
26 дней назад

(Composer is a dependency Manager for the PHP language. Prior to 2.2.29 ...)

CVSS3: 7
debian
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 ...

EPSS

Процентиль: 3%
0.00132
Низкий

7 High

CVSS3

Дефекты

CWE-22