Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59948

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7

Описание

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.

A flaw was found in Composer, a dependency manager for the PHP language. A remote attacker could exploit this vulnerability by providing a maliciously crafted package from an untrusted source. During installation or update, Composer's improper validation of package names allows it to write attacker-controlled files outside of designated directories. This could lead to arbitrary file write, potentially compromising the integrity of the system.

Отчет

Red Hat ships Composer version 2.10.2 in its products, which already includes the fix for this issue. No action is required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened ImagescomposerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2498211composer/composer: Composer: Arbitrary file write via crafted package name

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.

CVSS3: 7
nvd
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.

CVSS3: 7
debian
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 ...

CVSS3: 7
github
14 дней назад

Composer: Arbitrary file write outside vendor via malicious transitive package name

suse-cvrf
17 дней назад

Security update for php-composer2

7 High

CVSS3