CVE-2026-59944 | Composer up to 2.2.29/2.10.2 Symlink installed.json symlink

SecurityVulns

A vulnerability, which was classified as problematic, was found in Composer up to 2.2.29/2.10.2. The affected element is an unknown function of the file vendor/composer/installed.json of the component Symlink. Such manipulation leads to symlink following.

This vulnerability is documented as CVE-2026-59944. The attack needs to be performed locally. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More