UBUNTU-CVE-2026-59948
Composer, a PHP dependency manager, has a vulnerability in versions prior to 2.2.29 and 2.10.2 where a malicious package from an untrusted repository can cause files to be written outside the intended directories during install or update. This occurs due to improper validation of package names before dependency resolution. The issue is fixed in versions 2.2.29 and 2.10.2.
AI Analysis
Technical Summary
Composer versions before 2.2.29 and 2.10.2 allow a maliciously crafted package from untrusted repositories (other than Packagist.org or Private Packagist) to write attacker-controlled files outside the vendor directory and project root during install or update. This is caused by insufficient validation of invalid package names before dependency resolution results are written or installed. The vulnerability is addressed in Composer versions 2.2.29 and 2.10.2.
Potential Impact
An attacker controlling a package in an untrusted repository can cause Composer to write files outside the expected directories, potentially leading to arbitrary file write and compromise of the project environment. This could result in full confidentiality, integrity, and availability impact on the affected system as indicated by the CVSS vector.
Mitigation Recommendations
Upgrade Composer to version 2.2.29 or later, or 2.10.2 or later, where this vulnerability is fixed. No other mitigations are specified. Patch status is confirmed fixed in these versions.
UBUNTU-CVE-2026-59948
Description
Composer, a PHP dependency manager, has a vulnerability in versions prior to 2.2.29 and 2.10.2 where a malicious package from an untrusted repository can cause files to be written outside the intended directories during install or update. This occurs due to improper validation of package names before dependency resolution. The issue is fixed in versions 2.2.29 and 2.10.2.
CVSS v3.1
Score 7.0high
Affected software
pkg:deb/ubuntu/[email protected]~beta2-1ubuntu0.1~esm2?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]~esm2?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]~esm2?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Composer versions before 2.2.29 and 2.10.2 allow a maliciously crafted package from untrusted repositories (other than Packagist.org or Private Packagist) to write attacker-controlled files outside the vendor directory and project root during install or update. This is caused by insufficient validation of invalid package names before dependency resolution results are written or installed. The vulnerability is addressed in Composer versions 2.2.29 and 2.10.2.
Potential Impact
An attacker controlling a package in an untrusted repository can cause Composer to write files outside the expected directories, potentially leading to arbitrary file write and compromise of the project environment. This could result in full confidentiality, integrity, and availability impact on the affected system as indicated by the CVSS vector.
Mitigation Recommendations
Upgrade Composer to version 2.2.29 or later, or 2.10.2 or later, where this vulnerability is fixed. No other mitigations are specified. Patch status is confirmed fixed in these versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-59948
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b44c68715ace43d6b5d1
Added to database: 07/16/2026, 10:37:00 UTC
Last enriched: 07/16/2026, 11:28:26 UTC
Last updated: 07/31/2026, 19:24:46 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.