CVE-2026-59944 | Composer up to 2.2.29/2.10.2 Symlink installed.json symlink
A vulnerability, which was classified as problematic, was found in Composer up to 2.2.29/2.10.2. The affected element is an unknown function of the file vendor/composer/installed.json of the component Symlink. Such manipulation leads to symlink following.
This vulnerability is documented as CVE-2026-59944. The attack needs to be performed locally. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More