SCA: security update for composer/composer (GHSA-96h3-5x6v-m776)

medium Tenable Self-Hosted Container Security Plugin ID 471971

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3,
a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because
Composer validates literal parent-directory segments only during dependency resolution, while the symlink
and installed-metadata paths described by the advisory skip that validation. A package can ship an in-
package binary symlink that resolves outside its installation directory, or attacker-influenced
vendor/composer/installed.json metadata can provide an escaping binary path during a reinstall or
regeneration of missing vendor/bin entries. The installed-metadata path is reachable only when the vendor
directory was not populated by the same validated install run, such as when it is restored from an
untrusted cache, copied from an earlier build stage, carried over from an older Composer run, or writable
by a lower-trust build step. Composer can follow the path, change the external target's permissions to
make it world-readable and executable, and create a runnable vendor/bin proxy to that external file. The
issue does not directly read or transmit data and does not by itself provide remote code execution. This
issue is fixed in versions 2.2.30 and 2.10.3. (CVE-2026-59944)

Solution

Update the composer/composer library and its related packages to version 2.10.3 or later.

See Also

https://github.com/advisories/GHSA-96h3-5x6v-m776

Plugin Details

Severity: Medium

ID: 471971

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 95.89

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:P/A:N

CVSS Score Source: CVE-2026-59944

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/2/2026

Vulnerability Publication Date: 8/27/2026

Reference Information

CVE: CVE-2026-59944