Known vulnerabilities in composer

Software: composer
Software CPE: cpe:2.3:a:getcomposer.org:composer:*:*:*:*:*:*:*:*
Total vulnerabilities: 14
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting composer composer is affected by 14 known vulnerabilities: 8 high, 4 medium, 2 low Critical High Medium Low

Vulnerabilities (14)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136613 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59946
CWE-22 Medium
No
No
2.2.29, 2.10.2 01.07.2026 SB2026070158
SB20260721146
#VU136612 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59948
CWE-22 Medium
No
No
2.2.29, 2.10.2 01.07.2026 SB2026070158
SB20260721146
#VU136611 - Information Exposure Through Log Files
CVE-2026-59947
CWE-532 Low
No
No
2.2.29, 2.10.2 01.07.2026 SB2026070158
SB20260721146
#VU131373 - Exposure of sensitive information to an unauthorized actor
CVE-2026-45793
CWE-200 Medium
No
No
1.10.28, 2.2.28, 2.9.8 13.05.2026 SB2026051396
SB20260721146
#VU125895 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-40176
CWE-78 High
No
No
2.2.27, 2.9.6 14.04.2026 SB2026041445
SB2026041481
SB2026041482
and 8 more
#VU125894 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-40261
CWE-78 High
No
No
2.2.27, 2.9.6 14.04.2026 SB2026041445
SB2026041481
SB2026041482
and 8 more
#VU125893 - Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2025-67746
CWE-150 Medium
No
No
2.2.26, 2.9.3 14.04.2026 SB2026041444
SB2026041449
SB2026041450
and 2 more
#VU91685 - Command injection
CVE-2024-35242
CWE-77 High
No
No
2.2.24, 2.7.7 11.06.2024 SB2024061107
SB2024061108
SB2024061109
and 6 more
#VU91684 - Command injection
CVE-2024-35241
CWE-77 High
No
No
2.2.24, 2.7.7 11.06.2024 SB2024061107
SB2024061108
SB2024061109
and 7 more
#VU86276 - Incorrect Default Permissions
CVE-2024-24821
CWE-276 Low
No
No
2.2.23, 2.7.0 08.02.2024 SB2024020870
SB2024021508
SB2024022241
and 3 more
#VU81296 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-43655
CWE-94 High
No
No
1.10.27, 2.2.21, 2.6.4 29.09.2023 SB2023092947
SB2023092956
SB2023092957
and 13 more
#VU62312 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-24828
CWE-78 High
No
No
1.10.26, 2.2.12, 2.3.5 14.04.2022 SB2022041401
SB2022042017
SB2022090517
and 7 more
#VU57096 - Command injection
CVE-2021-41116
CWE-77 High
No
No
1.10.23, 2.1.9 06.10.2021 SB2021100610
SB2022042017
SB2022041434
#VU52777 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-29472
CWE-94 High
No
No
1.10.22, 2.0.13 30.04.2021 SB2021043007
SB2021043008
SB2021051726
and 3 more