securityonline.info 8/31/2026, 2:31:50 AM · external

High-Severity Composer Flaw Enables Command Execution

High-Severity Composer Flaw Enables Command Execution
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

COMPOSER , a widely used PHP package manager, patched two critical security vulnerabilities on August 27, 2026. The first vulnerability (CVE-2026-59944) allows malicious packages to escape their directory, while the second allows arbitrary command execution via a crafted Perforce URL. Both issues are addressed in Composer versions 2.10.3 and 2.2.30. The flaws affect versions from 1.0 to 2.2.30 and 2.3.0 to 2.10.3, with recommendations to update to the latest versions immediately to mitigate risks. Temporary measures include removing the p4 client from the PATH if not in use and restricting repositories to trusted sources.

View Primary Source Via securityonline.info

Article by CyberSIXT