RHSA-2026:63151
Vulnerability from csaf_redhat - Published: 2026-09-03 11:17 - Updated: 2026-09-21 11:31A flaw was found in Composer, a dependency manager for PHP. A malicious or compromised dependency can bypass existing security measures designed to prevent unauthorized binary path execution. This can occur when Composer processes untrusted cached data or older build artifacts, allowing it to follow symlinked paths outside of its intended installation directory. As a result, Composer may change the permissions of external files to make them executable and create proxy entries, potentially leading to the execution of unauthorized binaries.
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms | — |
Vendor Fix
fix
Workaround
|
|
| Unresolved product id: Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms | — |
Vendor Fix
fix
Workaround
|
|
| Unresolved product id: Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src | — |
Vendor Fix
fix
Workaround
|
A flaw was found in Composer. A malicious dependency package from a custom Composer repository or an untrusted `composer.lock` file could exploit a vulnerability in how Composer handles Perforce source URLs. By setting `source.type` to `perforce` and `source.url` to an `rsh:` or `jsh:` P4PORT value, an attacker could cause the Perforce `p4` client to execute arbitrary local commands. This could lead to arbitrary code execution with the privileges of the user or continuous integration (CI) account running Composer.
{
"document": {
"aggregate_severity": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"text": "Important"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "An update for Red Hat Hardened Images RPMs is now available.",
"title": "Topic"
},
{
"category": "general",
"text": "This update includes the following RPMs:\n\ncomposer:\n * composer-2.10.3-1.hum1 (noarch)\n * composer-2.10.3-1.hum1.src (src)",
"title": "Details"
},
{
"category": "legal_disclaimer",
"text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
"title": "Terms of Use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://access.redhat.com/security/team/contact/",
"issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
"name": "Red Hat Product Security",
"namespace": "https://www.redhat.com"
},
"references": [
{
"category": "self",
"summary": "https://access.redhat.com/errata/RHSA-2026:63151",
"url": "https://access.redhat.com/errata/RHSA-2026:63151"
},
{
"category": "external",
"summary": "https://images.redhat.com/",
"url": "https://images.redhat.com/"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-84361",
"url": "https://access.redhat.com/security/cve/CVE-2026-84361"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/updates/classification/",
"url": "https://access.redhat.com/security/updates/classification/"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-59944",
"url": "https://access.redhat.com/security/cve/CVE-2026-59944"
},
{
"category": "self",
"summary": "Canonical URL",
"url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63151.json"
}
],
"title": "Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update",
"tracking": {
"current_release_date": "2026-09-21T11:31:23+00:00",
"generator": {
"date": "2026-09-21T11:31:23+00:00",
"engine": {
"name": "Red Hat SDEngine",
"version": "5.4.0"
}
},
"id": "RHSA-2026:63151",
"initial_release_date": "2026-09-03T11:17:00+00:00",
"revision_history": [
{
"date": "2026-09-03T11:17:00+00:00",
"number": "1",
"summary": "Initial version"
},
{
"date": "2026-09-17T16:15:31+00:00",
"number": "2",
"summary": "Last updated version"
},
{
"date": "2026-09-21T11:31:23+00:00",
"number": "3",
"summary": "Last generated version"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Hardened Images",
"product": {
"name": "Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:hummingbird:1"
}
}
}
],
"category": "product_family",
"name": "Red Hat Hardened Images"
},
{
"branches": [
{
"category": "product_version",
"name": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"product": {
"name": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"product_id": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/composer@2.10.3-1.hum1?arch=noarch\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
}
}
},
{
"category": "product_version",
"name": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"product": {
"name": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"product_id": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/composer@2.10.3-1.hum1?arch=noarch\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
}
}
}
],
"category": "architecture",
"name": "noarch"
},
{
"branches": [
{
"category": "product_version",
"name": "composer-0:2.10.3-1.hum1@src",
"product": {
"name": "composer-0:2.10.3-1.hum1@src",
"product_id": "composer-0:2.10.3-1.hum1@src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/composer@2.10.3-1.hum1?arch=src\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-source-rpms"
}
}
}
],
"category": "architecture",
"name": "src"
}
],
"category": "vendor",
"name": "Red Hat"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms"
},
"product_reference": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms"
},
"product_reference": "composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "composer-0:2.10.3-1.hum1@src as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
},
"product_reference": "composer-0:2.10.3-1.hum1@src",
"relates_to_product_reference": "Red Hat Hardened Images"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-59944",
"cwe": {
"id": "CWE-59",
"name": "Improper Link Resolution Before File Access (\u0027Link Following\u0027)"
},
"discovery_date": "2026-09-16T16:24:11.759313+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2535546"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Composer, a dependency manager for PHP. A malicious or compromised dependency can bypass existing security measures designed to prevent unauthorized binary path execution. This can occur when Composer processes untrusted cached data or older build artifacts, allowing it to follow symlinked paths outside of its intended installation directory. As a result, Composer may change the permissions of external files to make them executable and create proxy entries, potentially leading to the execution of unauthorized binaries.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "composer: Composer: Security bypass allows execution of unauthorized binaries via symlinked paths",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-59944"
},
{
"category": "external",
"summary": "RHBZ#2535546",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535546"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-59944",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-59944"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-59944",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59944"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/commit/53b8bb4c24697b2f00a18cf1ef35a10392701b89",
"url": "https://github.com/composer/composer/commit/53b8bb4c24697b2f00a18cf1ef35a10392701b89"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/commit/ad649fdfdf8ed826d4a34e0e5690c76a0b4833aa",
"url": "https://github.com/composer/composer/commit/ad649fdfdf8ed826d4a34e0e5690c76a0b4833aa"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/releases/tag/2.10.3",
"url": "https://github.com/composer/composer/releases/tag/2.10.3"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/releases/tag/2.2.30",
"url": "https://github.com/composer/composer/releases/tag/2.2.30"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/security/advisories/GHSA-96h3-5x6v-m776",
"url": "https://github.com/composer/composer/security/advisories/GHSA-96h3-5x6v-m776"
}
],
"release_date": "2026-09-16T16:09:43.258000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-09-03T11:17:00+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:63151"
},
{
"category": "workaround",
"details": "Ensure the integrity of Composer\u0027s `vendor` directory and associated metadata. Avoid restoring `vendor` directories from untrusted caches or allowing lower-trust processes to modify them. Implement strict access controls on Composer project directories and perform Composer operations in a trusted, isolated build environment to prevent the introduction of malicious symlinks or metadata. This operational control may require adjustments to existing CI/CD pipelines or build processes.",
"product_ids": [
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
]
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 5.0,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
]
}
],
"threats": [
{
"category": "impact",
"details": "Moderate"
}
],
"title": "composer: Composer: Security bypass allows execution of unauthorized binaries via symlinked paths"
},
{
"cve": "CVE-2026-84361",
"cwe": {
"id": "CWE-78",
"name": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)"
},
"discovery_date": "2026-09-01T20:21:06.509116+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2527051"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Composer. A malicious dependency package from a custom Composer repository or an untrusted `composer.lock` file could exploit a vulnerability in how Composer handles Perforce source URLs. By setting `source.type` to `perforce` and `source.url` to an `rsh:` or `jsh:` P4PORT value, an attacker could cause the Perforce `p4` client to execute arbitrary local commands. This could lead to arbitrary code execution with the privileges of the user or continuous integration (CI) account running Composer.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "composer: Composer: Arbitrary code execution via malicious Perforce source URL",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-84361"
},
{
"category": "external",
"summary": "RHBZ#2527051",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2527051"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-84361",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-84361"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-84361",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84361"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/commit/0aac50528e83ed635cf788333635897469440220",
"url": "https://github.com/composer/composer/commit/0aac50528e83ed635cf788333635897469440220"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af",
"url": "https://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/releases/tag/2.10.3",
"url": "https://github.com/composer/composer/releases/tag/2.10.3"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/releases/tag/2.2.30",
"url": "https://github.com/composer/composer/releases/tag/2.2.30"
},
{
"category": "external",
"summary": "https://github.com/composer/composer/security/advisories/GHSA-rvx4-ffvw-m9q3",
"url": "https://github.com/composer/composer/security/advisories/GHSA-rvx4-ffvw-m9q3"
}
],
"release_date": "2026-09-01T20:06:48.375000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-09-03T11:17:00+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:63151"
},
{
"category": "workaround",
"details": "To mitigate this issue, avoid installing the Perforce `p4` client on systems where Composer is used, unless explicitly required. Additionally, ensure that Composer only processes dependencies from trusted repositories and `composer.lock` files to prevent the introduction of malicious `source.url` values.",
"product_ids": [
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
]
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:composer-0:2.10.3-1.hum1@src"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "composer: Composer: Arbitrary code execution via malicious Perforce source URL"
}
]
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.