VDB
CVE-2026-59944
CVE-2026-59944
PUBLISHED
CVSS 6.099999904632568 MEDIUM
Composer: CVE-2026-59946 fix bypass via symlinked package bin path
EPSS 0.32% · 23.1th percentile
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
EPSS Score
0.32%
23.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | composer | 1.0.0, 2.3.0, 1.0.0 |
Timeline
- Aug 28, 2026 CVE Published
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 6, 2026 EPSS Score
- Oct 6, 2026 Security Advisory
References
- https://github.com/composer/composer/commit/53b8bb4c24697b2f00a18cf1ef35a10392701b89 url
- https://github.com/composer/composer/commit/ad649fdfdf8ed826d4a34e0e5690c76a0b4833aa url
- https://github.com/composer/composer/releases/tag/2.10.3 url
- https://github.com/composer/composer/releases/tag/2.2.30 url
- https://github.com/composer/composer/security/advisories/GHSA-96h3-5x6v-m776 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-59944 url