CVE-2026-59944 Affects Composer Versions Still Compatible With Drupal 11

Composer 2.10.3 and 2.2.30 Set the Patched Baseline
Security graphic with a shield and gear icon. Text reads "Drupal Builds Need a Composer Version Check. CVE-2026-59944 affects Composer releases still compatible with Drupal 11 and is fixed in 2.10.3 and 2.2.30."

Running a Drupal 11 site on a supported Composer version does not by itself mean the Composer installation is protected from CVE-2026-59944. The vulnerability affects Composer releases from 2.3.0 up to, but not including, 2.10.3, while Drupal 11 requires Composer 2.7.0 or later. Composer 2.10.3 and the 2.2 LTS fix in 2.2.30 address the issue.

The flaw affects how Composer handles package binaries. A malicious or compromised dependency can declare a binary as a symbolic link that resolves outside its own package directory. Composer may then change permissions on the outside file and create a runnable vendor/bin proxy pointing to it.

GitLab's advisory rates the issue Medium at 6.1 under CVSS 3.1 and classifies it under path traversal, improper link resolution and incorrect permission assignment. The Composer advisory says the issue is not direct remote code execution and does not itself give an attacker a way to read or receive data remotely.

The more realistic risk is in build or deployment environments. Composer's advisory highlights cases where a vendor directory is restored from a shared or untrusted CI cache, copied from an earlier container stage, carried over from an older Composer installation or made writable by a lower-trust build step. A normal install of a malicious package can also trigger the issue when one of its declared binaries is a symlink escaping the package directory.

The patched releases validate that each declared binary resolves inside the package being installed before Composer changes the file or exposes it through vendor/bin. Paths that resolve outside the package directory are skipped with a warning.

Drupal 11 Compatibility Does Not Guarantee a Patched Composer

Drupal.org documents Composer 2.7.0 or later as the minimum requirement for Drupal 11. That leaves Composer versions from 2.7.0 through 2.10.2 inside the affected range for CVE-2026-59944.

The vulnerability is in Composer rather than Drupal core. No Drupal core security release is required to address it. The relevant update is the Composer executable used to install and update Drupal core, contributed projects and PHP dependencies.

That executable can differ between environments. A developer workstation, CI runner, container image and production deployment process may each use a separate Composer installation, so checking only the version on one machine can miss an affected copy elsewhere in the delivery pipeline.

The Fix Shipped Before the CVE Was Publicised

Composer released versions 2.10.3 and 2.2.30 on 27 August 2026. The 2.10.3 release notes describe the security change as validation of package binary paths against path traversal using symlinks and identify both GHSA-96h3-5x6v-m776 and CVE-2026-59944.

OSV records the GitHub-reviewed advisory as published on 2 October, while GitLab also lists the affected and fixed version ranges. The later public advisory date therefore does not mean the fix was released in October; patched Composer builds had already been available since August.

Projects on the current Composer line should update to at least 2.10.3. Environments intentionally remaining on the Composer 2.2 line should use at least 2.2.30. The Composer advisory states that upgrading is the only complete fix.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Related Organizations

Upcoming Events

Latest Opportunities