CVE-2026-59944 is a symlink-based path-traversal vulnerability in Composer package binary processing. A malicious or compromised dependency can declare a binary path that resolves through a symbolic link to a target outside the dependency's installation directory. Vulnerable Composer versions can follow that link while installing the package, register the external target in the project binary directory, and modify its permissions. The issue bypasses earlier validation that rejected literal parent-directory path segments because validation did not reliably account for symbolic-link resolution and restored dependency metadata. Composer 2.10.3 and 2.2.30 validate that declared binaries resolve within the installed package directory and skip unsafe declarations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A moderate-severity Composer path traversal and symbolic-link handling flaw that permits a malicious package binary symlink to resolve outside its package directory. During installation, Composer can change permissions on the external target and register it under vendor/bin, potentially exposing previously restricted files on shared or multi-tenant systems.
A network-accessible critical vulnerability tracked as CVE-2026-59944, identified by a Nessus unpatched-vulnerability plugin as affecting Debian Linux 11.0, 12.0, 13.0, and 14.0. The supplied CVSS v3.0 vector indicates no privileges or user interaction are required and potential high impact to confidentiality, integrity, and availability; the specific technical flaw is not stated.
A critical network-reachable vulnerability affecting FreeBSD Composer packages for PHP 8.2 through 8.5, with no privileges or user interaction required and potential high impact to confidentiality, integrity, and availability.
A path-traversal vulnerability involving symlinks in Composer package binary paths. Composer 2.10.3 adds validation to address it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.