
Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files
A newly disclosed security flaw in Composer, the widely used dependency manager for PHP, could allow a malicious or compromised package to alter permissions on files located outside its own installation directory. The issue, tracked as CVE-2026-59944, can expose sensitive files on shared or multi-tenant systems when vulnerable Composer versions process unsafe package binary paths. […]
The post Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files appeared first on Cyber Security News.