PKSA-zcdk-qnhk-hq2g Security Advisory
-
[HIGH] Composer: Arbitrary file write outside vendor via malicious transitive package name
PKSA-zcdk-qnhk-hq2g CVE-2026-59948 GHSA-499r-g7pc-vmp9
Affected package: composer/composer
Affected version: >=1.0.0,<2.2.29|>=2.3.0,<2.10.2
Reported by:
GitHub