GHSA-96h3-5x6v-m776: Path Traversal

Published Oct 2, 2026
·
Updated

Summary

A malicious or compromised Composer package could, when installed as a dependency, cause Composer to change the permissions of a file outside that package's own directory and to register a runnable vendor/bin command that points at that outside file. This is a path traversal and link following issue. It is not remote code execution, the attacker gains no ability to read or receive your data directly. The risk is that a file which was readable only by its owner, but modifiable by Composer, can be made world readable and executable, which is enough to expose its contents on a shared or multi tenant host. The earlier hardening from GHSA-gjfg-22fp-rrxx can be bypassed, since it only rejected literal .. path segments in a package's declared binaries, and was only applied in a single place during dependency resolution.

Am I affected?

You can be affected if a malicious or compromised package, including a transitive dependency, is installed in your project, and either of the following is true:

- The dependency package ships one of its declared binaries as a symbolic link that resolves to a location outside the package's own directory. Nothing beyond a normal install or update is required. - Or, the recorded metadata of your installed dependencies (vendor/composer/installed.json) declares a binary path that escapes the package's directory. Composer regenerates missing binaries from that recorded metadata at the end of an install, and uses this metadata for reinstalls of the same package. In both of these cases the validation applied during dependency resolution is skipped. This situation is only reachable when your vendor directory is not populated from the same install run, which performs validation. For example a vendor directory restored from a shared or untrusted CI cache, copied in from an earlier container build stage, carried over from a Composer older than 2.10.2 or 2.2.29, or writable by a lower trust build step, could contain such malicious data.

The most realistic way to get hit is a composer install in a build or deploy step that reuses a vendor directory produced elsewhere, since the permission change is applied silently and with the privileges of the user running Composer.

Patched versions

Composer now verifies that each declared binary resolves to a path inside the installing package's own directory before it touches the file, and skips any binary that resolves outside it with a warning. Update to the patched releases (2.10.3 and 2.2.30).

Workarounds

Upgrading is the only complete fix.

Affected Software

2 affected componentsFixes available
composer/composer/composer>=1.0<2.2.30
2.2.30
composer/composer/composer>=2.3.0<2.10.3
2.10.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/composer/composer to a version that resolves this vulnerability.

    Fixed in 2.2.30
  2. Upgrade

    Upgrade composer/composer/composer to a version that resolves this vulnerability.

    Fixed in 2.10.3
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.10.3
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.2.30

Event History

Oct 2, 2026
Advisory Published
via GitHub·07:14 PM
Data Sourced
via GitHub·07:14 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which projects are realistically exposed?

Projects are exposed if they install a malicious or compromised direct or transitive Composer dependency that ships a declared binary as a symbolic link resolving outside that package's directory. A normal install or update is sufficient for that condition to matter.

2

What does an attacker need in order to exploit this?

The attacker needs a malicious or compromised Composer package to be installed as a dependency and must use a declared binary that causes Composer to follow a path outside the package directory. User interaction is required according to the advisory's severity vector.

3

What is the practical impact of successful exploitation?

Composer can change permissions on an outside file and register a runnable vendor/bin command pointing to it. A file readable only by its owner but modifiable by Composer can become world-readable and executable, potentially exposing its contents on a shared or multi-tenant host; the issue does not directly give the attacker remote code execution or direct access to receive data.

4

How can I check whether a dependency is attempting this?

Inspect declared binaries from direct and transitive dependencies, especially packages that ship those binaries as symbolic links. Treat a binary whose resolved target is outside its own package directory as an affected condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203