CVE-2026-59948

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-08 20:16

Updated : 2026-07-10 19:14


NVD link : CVE-2026-59948

Mitre link : CVE-2026-59948

CVE.ORG link : CVE-2026-59948


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-787

Out-of-bounds Write