composer/composer Security Advisories for 1.5.5 (12)
-
[MEDIUM] Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
PKSA-ddsx-fjz2-sbs3 CVE-2026-59944 GHSA-96h3-5x6v-m776
Affected version: >=1.0,<2.2.30|>=2.3.0,<2.10.3
Reported by:
GitHub -
[HIGH] Composer arbitrary command execution via a malicious package's Perforce source URL
PKSA-ym19-cy3j-z6df CVE-2026-84361 GHSA-rvx4-ffvw-m9q3
Affected version: >=1.0,<2.2.30|>=2.3.0,<2.10.3
Reported by:
GitHub -
[MEDIUM] Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
PKSA-q3ht-3g42-rg8f CVE-2026-59946 GHSA-gjfg-22fp-rrxx
Affected version: >=1.0.0,<2.2.29|>=2.3.0,<2.10.2
Reported by:
GitHub -
[MEDIUM] Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
PKSA-4pm6-g63v-5rkr CVE-2026-59947 GHSA-g6xq-892h-64w3
Affected version: >=1.0.0,<2.2.29|>=2.3.0,<2.10.2
Reported by:
GitHub -
[HIGH] Composer: Arbitrary file write outside vendor via malicious transitive package name
PKSA-zcdk-qnhk-hq2g CVE-2026-59948 GHSA-499r-g7pc-vmp9
Affected version: >=1.0.0,<2.2.29|>=2.3.0,<2.10.2
Reported by:
GitHub -
[HIGH] Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
PKSA-pwvr-3754-v57r CVE-2026-45793 GHSA-f9f8-rm49-7jv2
Affected version: >=2.3,<2.9.8|>=2.0.0,<2.2.28|>=1.0,<1.10.28
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Command injection via malicious Perforce source reference/url
PKSA-t5r2-p5q9-mtpn CVE-2026-40261 GHSA-gqw4-4w2p-838q
Affected version: >=2.3,<2.9.6|>=1.0,<2.2.27
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Command injection via malicious Perforce repository definition
PKSA-6bp1-9hfj-2cgv CVE-2026-40176 GHSA-wg36-wvj6-r67p
Affected version: >=2.3,<2.9.6|>=1.0,<2.2.27
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Composer Remote Code Execution vulnerability via web-accessible composer.phar
PKSA-m1ph-vmbx-2xd3 CVE-2023-43655 GHSA-jm6m-4632-36hf
Affected version: >=2.3.0,<2.6.4|>=2.0.0,<2.2.22|<1.10.27
Reported by:
GitHub -
[HIGH] Missing input validation can lead to command execution in composer
PKSA-6zmq-d6mk-r5wm CVE-2022-24828 GHSA-x7cr-6qr6-2hh6
Affected version: >=2.3,<2.3.5|>=2.0,<2.2.12|<1.10.26
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Improper escaping of command arguments on Windows leading to command injection
PKSA-93hy-9dc1-gbwt CVE-2021-41116 GHSA-frqg-7g38-6gcf
Affected version: >=2.0.0-alpha1,<2.1.9|<1.10.23
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Missing argument delimiter can lead to command execution via VCS repository URLs or source download URLs on systems with Mercurial
PKSA-9p8h-97x3-qxpm CVE-2021-29472 GHSA-h5h8-pc6h-jvvx
Affected version: >=2.0.0-alpha1,<2.0.13|<1.10.22
Reported by:
FriendsOfPHP/security-advisories, GitHub