{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/composer--2.3.0--2.10.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7,"id":"CVE-2026-59948"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Composer (\u003c 2.2.29)","Composer (\u003e= 2.3.0, \u003c 2.10.2)"],"_cs_severities":["high"],"_cs_tags":["composer","php","supply-chain","arbitrary-file-write","code-execution","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Composer"],"content_html":"\u003cp\u003eA high-severity supply-chain vulnerability (CVE-2026-59948) has been identified in Composer, the popular PHP dependency manager. This flaw allows a malicious actor to achieve arbitrary file writes outside a project's intended \u003ccode\u003evendor/\u003c/code\u003e directory and even outside the project root. This occurs when Composer attempts to install or update a dependency from an untrusted third-party repository, and that dependency has been maliciously crafted with an invalid package name that Composer fails to validate correctly. The vulnerability affects Composer versions older than 2.2.29 and versions between 2.3.0 and 2.10.2, as well as all 1.x versions. Attackers can exploit this to write arbitrary files such as shell startup files, SSH \u003ccode\u003eauthorized_keys\u003c/code\u003e, or cron entries, leading to code execution outside the expected project context. This vulnerability is not remotely exploitable against a machine directly but requires the presence of a malicious or compromised package within the dependency graph.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious PHP package with an invalid \u003ccode\u003evendor/package\u003c/code\u003e name format.\u003c/li\u003e\n\u003cli\u003eThe attacker publishes this malicious package to an untrusted third-party Composer repository (not Packagist.org or Private Packagist).\u003c/li\u003e\n\u003cli\u003eA victim's Composer project is configured to use this untrusted repository for dependency resolution.\u003c/li\u003e\n\u003cli\u003eThe victim executes \u003ccode\u003ecomposer install\u003c/code\u003e or \u003ccode\u003ecomposer update\u003c/code\u003e within their project, causing Composer to resolve and attempt to install dependencies, including the malicious package.\u003c/li\u003e\n\u003cli\u003eComposer processes the malicious package, and due to a lack of proper validation, constructs a file path outside the \u003ccode\u003evendor/\u003c/code\u003e directory using the invalid package name.\u003c/li\u003e\n\u003cli\u003eComposer writes attacker-controlled content (e.g., shell startup script, SSH authorized_keys entry, cron job definition) to the arbitrary file path on the victim's system.\u003c/li\u003e\n\u003cli\u003eUpon the next relevant event (e.g., system boot, SSH connection, cron execution), the attacker's payload is executed, leading to remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-59948 results in arbitrary file write capabilities, which can lead to full system compromise through code execution. This supply-chain vulnerability allows attackers to inject malicious code into critical system locations such as shell startup files, SSH \u003ccode\u003eauthorized_keys\u003c/code\u003e, or cron entries. This can grant attackers persistent access, elevate privileges, and ultimately allow them to take complete control of the compromised server. The scope of impact is broad, affecting any organization or individual using vulnerable Composer versions with untrusted third-party repositories.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Composer immediately to version \u003cstrong\u003e2.2.29\u003c/strong\u003e or \u003cstrong\u003e2.10.2\u003c/strong\u003e to remediate CVE-2026-59948. Composer 1.x users should upgrade to a safe 2.x release.\u003c/li\u003e\n\u003cli\u003eConfigure Composer to avoid untrusted third-party package repositories. Review your \u003ccode\u003ecomposer.json\u003c/code\u003e and global Composer configurations for untrusted sources.\u003c/li\u003e\n\u003cli\u003eIf using untrusted repositories is unavoidable, mirror them through an internal repository solution, such as Private Packagist, which performs package name validation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T19:17:13Z","date_published":"2026-07-20T19:17:13Z","id":"https://feed.craftedsignal.io/briefs/2026-07-composer-arbitrary-file-write/","summary":"A critical vulnerability, CVE-2026-59948, in Composer allows for arbitrary file write outside the project's vendor directory when processing a maliciously crafted package from an untrusted third-party repository during `install` or `update` operations, enabling code execution.","title":"Composer: Arbitrary File Write via Malicious Transitive Package Name","url":"https://feed.craftedsignal.io/briefs/2026-07-composer-arbitrary-file-write/"}],"language":"en","title":"CraftedSignal Threat Feed - Composer (\u003e= 2.3.0, \u003c 2.10.2)","version":"https://jsonfeed.org/version/1.1"}