Vulnerability GHSA-96h3-5x6v-m776

Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 hours ago
October 02, 2026 at 07:14 PM UTC
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.29 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.2
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.29 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.2

Summary

Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path

Details

Summary

A malicious or compromised Composer package could, when installed as a dependency, cause Composer to change the permissions of a file outside that package's own directory and to register a runnable vendor/bin command that points at that outside file. This is a path traversal and link following issue. It is not remote code execution, the attacker gains no ability to read or receive your data directly. The risk is that a file which was readable only by its owner, but modifiable by Composer, can be made world readable and executable, which is enough to expose its contents on a shared or multi tenant host. The earlier hardening from GHSA-gjfg-22fp-rrxx can be bypassed, since it only rejected literal .. path segments in a package's declared binaries, and was only applied in a single place during dependency resolution.

Am I affected?

You can be affected if a malicious or compromised package, including a transitive dependency, is installed in your project, and either of the following is true:

  • The dependency package ships one of its declared binaries as a symbolic link that resolves to a location outside the package's own directory. Nothing beyond a normal install or update is required.
  • Or, the recorded metadata of your installed dependencies (vendor/composer/installed.json) declares a binary path that escapes the package's directory. Composer regenerates missing binaries from that recorded metadata at the end of an install, and uses this metadata for reinstalls of the same package. In both of these cases the validation applied during dependency resolution is skipped. This situation is only reachable when your vendor directory is not populated from the same install run, which performs validation. For example a vendor directory restored from a shared or untrusted CI cache, copied in from an earlier container build stage, carried over from a Composer older than 2.10.2 or 2.2.29, or writable by a lower trust build step, could contain such malicious data.

The most realistic way to get hit is a composer install in a build or deploy step that reuses a vendor directory produced elsewhere, since the permission change is applied silently and with the privileges of the user running Composer.

Patched versions

Composer now verifies that each declared binary resolves to a path inside the installing package's own directory before it touches the file, and skips any binary that resolves outside it with a warning. Update to the patched releases (2.10.3 and 2.2.30).

Workarounds

Upgrading is the only complete fix.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
24 days ago
Composer arbitrary command execution via a malicious package's Perforce source URL
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.29 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.2 GHSA-rvx4-ffvw-m9q3
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.29 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.2 GHSA-rvx4-ffvw-m9q3
Medium Risk
2 months ago
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.28 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.1 GHSA-gjfg-22fp-rrxx
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.28 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.1 GHSA-gjfg-22fp-rrxx
Medium Risk
2 months ago
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.28 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.1 GHSA-g6xq-892h-64w3
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.28 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.1 GHSA-g6xq-892h-64w3
High Risk
2 months ago
Composer: Arbitrary file write outside vendor via malicious transitive package name
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.28 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.1 GHSA-499r-g7pc-vmp9
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.28 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.28 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.8 and 2.10.0 - 2.10.1 GHSA-499r-g7pc-vmp9
High Risk
4 months ago
Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.27 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.27 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.7 GHSA-f9f8-rm49-7jv2
1.0.0 - 1.0.3 and 1.1.0 - 1.1.3 and 1.2.0 - 1.2.4 and 1.3.0 - 1.5.6 and 1.6.0 - 1.6.5 and 1.7.0 - 1.9.3 and 1.10.0 - 1.10.27 and 2.0.0 - 2.0.14 and 2.1.0 - 2.1.14 and 2.2.0 - 2.2.27 and 2.3.0 - 2.3.10 and 2.4.0 - 2.8.12 and 2.9.0 - 2.9.7 GHSA-f9f8-rm49-7jv2
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
5 hours ago
October 02, 2026 at 07:14 PM UTC
Fixed (2.10.3)
1 month ago
August 27, 2026 at 11:34 AM UTC
Fixed (2.2.30)
1 month ago
August 27, 2026 at 11:34 AM UTC
Last Modified
4 hours ago
October 02, 2026 at 07:30 PM UTC