The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

The Php Times

Security — Ecosystem

Composer 2.2.30 fixes four security vulnerabilities


Composer 2.2.30 is a security release for the 2.2 LTS line.

COMPOSER RELEASES, August 27, 2026 curated by Sönke

It patches a path traversal issue via package bin symlinks (CVE-2026-59944), a command injection through malicious Perforce URLs, and two credential-leak fixes involving URL-embedded tokens and GitLab URL matching.

Composer 2.2.30 fixes four security vulnerabilities
Screenshot: Composer Releases ↗

Composer 2.2.30 is a security-only release for the 2.2 LTS branch, published on 27 August by Jordi Boggiano (Seldaek). The tag is signed and the release is marked immutable.

Four vulnerabilities are addressed. First, package bin paths are now validated against path traversal attacks that use symlinks, tracked as GHSA-96h3-5x6v-m776 and CVE-2026-59944. Second, a command injection via a malicious Perforce URL was fixed (GHSA-rvx4-ffvw-m9q3).

Two further fixes concern credential handling. URL-embedded usernames and tokens are now sanitized in additional places (PR #13045), and the matching of GitLab URLs was corrected so credentials cannot leak to the wrong domain (PR #13042).

Users still on the 2.2 line should update promptly. The full changelog covers 2.2.29 to 2.2.30.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

← Ecosystem — Page B1

"All the Code That's Fit to Ship" · The Daily Commit · Screen edition · Imprint · Privacy Policy