
Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files
A newly disclosed vulnerability in Composer could allow malicious or compromised PHP packages to alter permissions on files located outside their intended installation directory, potentially exposing sensitive data on shared and multi-tenant systems. Tracked as CVE-2026-59944, the flaw affects Composer versions 2.3.0 through 2.10.2 and versions 1.0 through 2.2.29. Composer has addressed the issue in […]
The post Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files appeared first on Cyber Security News.