CVE-2026-59948

Source
https://cve.org/CVERecord?id=CVE-2026-59948
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59948.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59948
Aliases
Downstream
Related
Published
2026-07-08T19:33:48.414Z
Modified
2026-08-04T18:41:58.212890041Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Composer: Arbitrary file write outside vendor via malicious transitive package name
Details

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59948.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22",
        "CWE-787"
    ]
}
References

Affected packages

Git / github.com/composer/composer

Affected ranges

Type
GIT
Repo
https://github.com/composer/composer
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.0"
        },
        {
            "fixed": "2.2.29"
        },
        {
            "introduced": "2.3.0"
        },
        {
            "fixed": "2.10.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.10.0
2.10.0-RC1
2.10.0-RC2
2.10.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.0-RC1
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0
2.9.0-RC1
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59948.json"