AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-59944.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

## Summary A malicious or compromised Composer package could, when installed as a dependency, cause Composer to change the permissions of a file outside that package's own directory and to register a runnable `vendor/bin` command that points at that outside file. This is a path traversal and link following issue. It is not remote code execution, the attacker gains no ability to read or receive your data directly. The risk is that a file which was readable only by its owner, but modifiable by Composer, can be made world readable and executable, which is enough to expose its contents on a shared or multi tenant host. The earlier hardening from GHSA-gjfg-22fp-rrxx can be bypassed, since it only rejected literal `..` path segments in a package's declared binaries, and was only applied in a single place during dependency resolution. ## Am I affected? You can be affected if a malicious or compromised package, including a transitive dependency, is installed in your project, and either of the following is true: - The dependency package ships one of its declared binaries as a symbolic link that resolves to a location outside the package's own directory. Nothing beyond a normal install or up

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-96h3-5x6v-m776

Open original source · Updated Oct 02, 2026

Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
composercomposer/composer>= 2.3.0, < 2.10.32.10.3
composercomposer/composer>= 1.0, < 2.2.302.2.30

Original records & references

PUBLISHED 2026-10-02T15:14:34-04:00
MODIFIED 2026-10-02T15:14:36-04:00
INGESTED 2026-10-06T11:45:17-04:00