composer has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-22 (3). Most affected products: composer/composer (4), composer (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Worst active — by depth score
CVE-2026-84361HighComposer is a dependency Manager for the PHP language53CVE-2026-59948High· 7.0Composer: Arbitrary file write outside vendor via malicious transitive package name39CVE-2026-59944Medium· 6.1Composer is a dependency Manager for the PHP language34CVE-2026-59946Medium· 6.1Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files34CVE-2026-59947Medium· 4.7Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)26
composer vulnerabilities
CVEs affecting composer, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-59944Medium· 6.1Composer is a dependency Manager for the PHP language
Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates litera…
CVE-2026-84361HighPoCComposer is a dependency Manager for the PHP language
Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url…
CVE-2026-59947Medium· 4.7Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
CVE-2026-59946Medium· 6.1Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
CVE-2026-59948High· 7.0Composer: Arbitrary file write outside vendor via malicious transitive package name
Composer: Arbitrary file write outside vendor via malicious transitive package name