Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestion detail

Untriaged
Permalink CVE-2026-59944
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 days, 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package subtitlecomposer
Composer: CVE-2026-59946 fix bypass via symlinked package bin path

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segments only during dependency resolution, while the symlink and installed-metadata paths described by the advisory skip that validation. A package can ship an in-package binary symlink that resolves outside its installation directory, or attacker-influenced vendor/composer/installed.json metadata can provide an escaping binary path during a reinstall or regeneration of missing vendor/bin entries. The installed-metadata path is reachable only when the vendor directory was not populated by the same validated install run, such as when it is restored from an untrusted cache, copied from an earlier build stage, carried over from an older Composer run, or writable by a lower-trust build step. Composer can follow the path, change the external target's permissions to make it world-readable and executable, and create a runnable vendor/bin proxy to that external file. The issue does not directly read or transmit data and does not by itself provide remote code execution. This issue is fixed in versions 2.2.30 and 2.10.3.

Affected products

composer
  • ==>= 2.3.0, < 2.10.3
  • ==>= 1.0.0, < 2.2.30

Matching in nixpkgs

pkgs.composer-require-checker

CLI tool to check whether a specific composer package uses imported symbols that aren't part of its direct composer dependencies

  • nixos-unstable -
  • nixos-26.05 -

pkgs.phpPackages.cyclonedx-php-composer

Composer plugin that facilitates the creation of a CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects

  • nixos-unstable -
    • nixos-unstable-small 5.2.0
  • nixos-26.05 -
    • nixos-26.05-small 5.2.0

pkgs.php82Packages.cyclonedx-php-composer

Composer plugin that facilitates the creation of a CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects

  • nixos-unstable -
    • nixos-unstable-small 5.2.0
  • nixos-26.05 -
    • nixos-26.05-small 5.2.0

pkgs.php83Packages.cyclonedx-php-composer

Composer plugin that facilitates the creation of a CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects

  • nixos-unstable -
    • nixos-unstable-small 5.2.0
  • nixos-26.05 -
    • nixos-26.05-small 5.2.0

pkgs.php84Packages.cyclonedx-php-composer

Composer plugin that facilitates the creation of a CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects

  • nixos-unstable -
    • nixos-unstable-small 5.2.0
  • nixos-26.05 -
    • nixos-26.05-small 5.2.0

pkgs.php85Packages.cyclonedx-php-composer

Composer plugin that facilitates the creation of a CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects

  • nixos-unstable -
    • nixos-unstable-small 5.2.0
  • nixos-26.05 -
    • nixos-26.05-small 5.2.0
Ignored packages (1)

pkgs.subtitlecomposer

Open source text-based subtitle editor

  • nixos-unstable -
    • nixos-unstable-small 0.8.2
  • nixos-26.05 -
    • nixos-26.05-small 0.8.2

Package maintainers