Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59946

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.

A flaw was found in Composer, a dependency manager for PHP. A malicious package can exploit a vulnerability in Composer's binary installation process by using specially crafted path segments. This allows an existing file on the host system to have its permissions changed to be world-readable and world-executable. This can lead to sensitive information disclosure and potentially allow an attacker to execute arbitrary code.

Отчет

Red Hat ships Composer version 2.10.2 in its products, which already includes the fix for this issue. Community distributions have been notified.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-279
https://bugzilla.redhat.com/show_bug.cgi?id=2498194composer: Composer: Insecure file permissions leading to information disclosure and potential execution

EPSS

Процентиль: 4%
0.00142
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.

CVSS3: 6.1
nvd
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.

CVSS3: 6.1
debian
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 ...

CVSS3: 6.1
github
14 дней назад

Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

suse-cvrf
17 дней назад

Security update for php-composer2

EPSS

Процентиль: 4%
0.00142
Низкий

5.6 Medium

CVSS3