<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:13:54 +0000</lastBuildDate>
    <item>
      <title>BIT-composer-2026-59946 — Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files</title>
      <link>https://cve.radiocsirt.org/vuln/bit-composer-2026-59946</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer&amp;#39;s binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer&amp;#39;s binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-composer-2026-59946</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-XS00515 — Security fix for CVE-2026-59946 applied in: composer 2.10.2-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-xs00515</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-xs00515</guid>
    </item>
    <item>
      <title>EUVD-2026-335374</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335374</link>
      <description>EUVD-2026-335374</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335374</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59946</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59946</link>
      <description>&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer&amp;#39;s binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer&amp;#39;s binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59946</guid>
    </item>
    <item>
      <title>GHSA-gjfg-22fp-rrxx — Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gjfg-22fp-rrxx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Composer package declares its executables in the `bin` field of its `composer.json`. When Composer installs a package, it processes each `bin` entry and changes the file mode of the corresponding file so it is executable.&lt;/p&gt;
&lt;p&gt;If a `bin` entry contains `..` path segments, it can resolve to a path outside the package&amp;#39;s own install directory. A malicious package can use this to make Composer run `chmod` against a file that already exists elsewhere on the machine. The resulting mode is world-readable and world-executable (0755 under the common umask of 022). This happens when the package is installed, e.g. during `composer install`, `composer update`, and `composer require`. Any dependency can trigger it, including a transitive dependency several levels deep.&lt;/p&gt;
&lt;p&gt;The vulnerability *changes file permissions only, and does not read, modify, or execute the contents of the target file, and it is not remote code execution*. The impact is to confidentiality: a file with deliberately restrictive permissions, such as a private key at mode 0600, can be made readable by other users on the same host.&lt;/p&gt;
&lt;p&gt;## Am I affected?&lt;/p&gt;
&lt;p&gt;We reviewed packagist.org data and found no evidence that any published package exploited this vulnerability. If you install packages only from packagist.org, you are not affected by any known exploitation.&lt;/p&gt;
&lt;p&gt;You are potentially affected if *all* of the following are true:&lt;/p&gt;
&lt;p&gt;- Your Composer project depends, directly or transitively, on a package you do not fully trust…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Composer package declares its executables in the `bin` field of its `composer.json`. When Composer installs a package, it processes each `bin` entry and changes the file mode of the corresponding file so it is executable.&lt;/p&gt;
&lt;p&gt;If a `bin` entry contains `..` path segments, it can resolve to a path outside the package&amp;#39;s own install directory. A malicious package can use this to make Composer run `chmod` against a file that already exists elsewhere on the machine. The resulting mode is world-readable and world-executable (0755 under the common umask of 022). This happens when the package is installed, e.g. during `composer install`, `composer update`, and `composer require`. Any dependency can trigger it, including a transitive dependency several levels deep.&lt;/p&gt;
&lt;p&gt;The vulnerability *changes file permissions only, and does not read, modify, or execute the contents of the target file, and it is not remote code execution*. The impact is to confidentiality: a file with deliberately restrictive permissions, such as a private key at mode 0600, can be made readable by other users on the same host.&lt;/p&gt;
&lt;p&gt;## Am I affected?&lt;/p&gt;
&lt;p&gt;We reviewed packagist.org data and found no evidence that any published package exploited this vulnerability. If you install packages only from packagist.org, you are not affected by any known exploitation.&lt;/p&gt;
&lt;p&gt;You are potentially affected if *all* of the following are true:&lt;/p&gt;
&lt;p&gt;- Your Composer project depends, directly or transitively, on a package you do not fully trust…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gjfg-22fp-rrxx</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11268-1 — php-composer2-2.10.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11268-1</link>
      <description>&lt;p&gt;php-composer2-2.10.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php-composer2-2.10.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11268-1</guid>
    </item>
    <item>
      <title>RHSA-2026:34854 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:34854</link>
      <description>&lt;p&gt;composer: Composer: Insecure file permissions leading to information disclosure and potential execution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;composer: Composer: Insecure file permissions leading to information disclosure and potential execution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:34854</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23116-1 — Security update for php-composer2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23116-1</link>
      <description>&lt;p&gt;Security update for php-composer2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php-composer2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23116-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59946</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59946</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer, Ubuntu:25.10: composer, Ubuntu:26.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer&amp;#39;s binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer, Ubuntu:25.10: composer, Ubuntu:26.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer&amp;#39;s binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59946</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2235 — Composer: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2235</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Composer ausnutzen, um Sicherheitsmechanismen zu umgehen, um beliebige Dateien zu schreiben oder um Informationen offenzulegen. Zur erfolgreichen Ausnutzung sind teilweise bestimmte Konfigurationen erforderlich.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Composer ausnutzen, um Sicherheitsmechanismen zu umgehen, um beliebige Dateien zu schreiben oder um Informationen offenzulegen. Zur erfolgreichen Ausnutzung sind teilweise bestimmte Konfigurationen erforderlich.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2235</guid>
    </item>
  </channel>
</rss>
