Directory Traversal Vulnerability in Composer Dependency Manager by Private Vendor
CVE-2026-59944

6.1MEDIUM

Key Information:

Vendor

Composer

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-59944?

The Composer dependency manager for PHP contains a directory traversal vulnerability that enables a malicious or compromised dependency to bypass previous binary-path hardening mechanisms. This issue arises when Composer validates literal parent-directory segments only during dependency resolution and fails to check symlink and installed-metadata paths. This flaw allows an attacker to use in-package binaries that resolve outside their installation directories or manipulate metadata to create proxies to external files. This could lead to altered file permissions making sensitive files accessible on the system. Mitigating actions require upgrading to safe versions 2.2.30 or 2.10.3.

Affected Version(s)

composer >= 1.0.0, < 2.2.30 < 1.0.0, 2.2.30

composer >= 2.3.0, < 2.10.3 < 2.3.0, 2.10.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.