Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files

A newly disclosed security flaw in Composer, the widely used dependency manager for PHP, could allow a malicious or compromised package to alter permissions on files located outside its own installation directory. The issue, tracked as CVE-2026-59944, can expose sensitive files on shared or multi-tenant systems when vulnerable Composer versions process unsafe package binary paths. […]

This article has been indexed from Cyber Security News

Read the original article: