<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:49:52.566170+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-composer-2026-59946</id>
    <title>BIT-composer-2026-59946 — Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files</title>
    <updated>2026-10-03T23:49:52.707802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: composer</p>
<p>Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-composer-2026-59946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-xs00515</id>
    <title>CLEANSTART-2026-XS00515 — Security fix for CVE-2026-59946 applied in: composer 2.10.2-r0</title>
    <updated>2026-10-03T23:49:52.707866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: composer</p>
<p>Security vulnerability affects the composer package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-xs00515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335374</id>
    <title>EUVD-2026-335374</title>
    <updated>2026-10-03T23:49:52.707890+00:00</updated>
    <content>EUVD-2026-335374</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59946</id>
    <title>fkie_cve-2026-59946</title>
    <updated>2026-10-03T23:49:52.707903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gjfg-22fp-rrxx</id>
    <title>GHSA-gjfg-22fp-rrxx — Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files</title>
    <updated>2026-10-03T23:49:52.707927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: composer/composer</p>
<p>## Summary</p>
<p>A Composer package declares its executables in the `bin` field of its `composer.json`. When Composer installs a package, it processes each `bin` entry and changes the file mode of the corresponding file so it is executable.</p>
<p>If a `bin` entry contains `..` path segments, it can resolve to a path outside the package's own install directory. A malicious package can use this to make Composer run `chmod` against a file that already exists elsewhere on the machine. The resulting mode is world-readable and world-executable (0755 under the common umask of 022). This happens when the package is installed, e.g. during `composer install`, `composer update`, and `composer require`. Any dependency can trigger it, including a transitive dependency several levels deep.</p>
<p>The vulnerability *changes file permissions only, and does not read, modify, or execute the contents of the target file, and it is not remote code execution*. The impact is to confidentiality: a file with deliberately restrictive permissions, such as a private key at mode 0600, can be made readable by other users on the same host.</p>
<p>## Am I affected?</p>
<p>We reviewed packagist.org data and found no evidence that any published package exploited this vulnerability. If you install packages only from packagist.org, you are not affected by any known exploitation.</p>
<p>You are potentially affected if *all* of the following are true:</p>
<p>- Your Composer project depends, directly or transitively, on a package you do not fully trust…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gjfg-22fp-rrxx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11268-1</id>
    <title>openSUSE-SU-2026:11268-1 — php-composer2-2.10.2-1.1 on GA media</title>
    <updated>2026-10-03T23:49:52.707974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>php-composer2-2.10.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11268-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:34854</id>
    <title>RHSA-2026:34854 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T23:49:52.707993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>composer: Composer: Insecure file permissions leading to information disclosure and potential execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:34854"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23116-1</id>
    <title>SUSE-SU-2026:23116-1 — Security update for php-composer2</title>
    <updated>2026-10-03T23:49:52.708009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for php-composer2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23116-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59946</id>
    <title>UBUNTU-CVE-2026-59946</title>
    <updated>2026-10-03T23:49:52.708027+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer, Ubuntu:25.10: composer, Ubuntu:26.04:LTS: composer</p>
<p>Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2235</id>
    <title>WID-SEC-W-2026-2235 — Composer: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:49:52.708056+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Composer ausnutzen, um Sicherheitsmechanismen zu umgehen, um beliebige Dateien zu schreiben oder um Informationen offenzulegen. Zur erfolgreichen Ausnutzung sind teilweise bestimmte Konfigurationen erforderlich.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2235"/>
  </entry>
</feed>
