CVE-2026-59944 Affects Composer Versions Still Compatible With Drupal 11
Running a Drupal 11 site on a supported Composer version does not by itself mean the Composer installation is protected from CVE-2026-59944. The vulnerability affects Composer releases from 2.3.0 up to, but not including, 2.10.3, while Drupal 11 requires Composer 2.7.0 or later. Composer 2.10.3 and the 2.2 LTS fix in 2.2.30 address the issue.
The flaw affects how Composer handles package binaries. A malicious or compromised dependency can declare a binary as a symbolic link that resolves outside its own package directory. Composer may then change permissions on the outside file and create a runnable vendor/bin proxy pointing to it.
GitLab's advisory rates the issue Medium at 6.1 under CVSS 3.1 and classifies it under path traversal, improper link resolution and incorrect permission assignment. The Composer advisory says the issue is not direct remote code execution and does not itself give an attacker a way to read or receive data remotely.
The more realistic risk is in build or deployment environments. Composer's advisory highlights cases where a vendor directory is restored from a shared or untrusted CI cache, copied from an earlier container stage, carried over from an older Composer installation or made writable by a lower-trust build step. A normal install of a malicious package can also trigger the issue when one of its declared binaries is a symlink escaping the package directory.
The patched releases validate that each declared binary resolves inside the package being installed before Composer changes the file or exposes it through vendor/bin. Paths that resolve outside the package directory are skipped with a warning.
Drupal 11 Compatibility Does Not Guarantee a Patched Composer
Drupal.org documents Composer 2.7.0 or later as the minimum requirement for Drupal 11. That leaves Composer versions from 2.7.0 through 2.10.2 inside the affected range for CVE-2026-59944.
The vulnerability is in Composer rather than Drupal core. No Drupal core security release is required to address it. The relevant update is the Composer executable used to install and update Drupal core, contributed projects and PHP dependencies.
That executable can differ between environments. A developer workstation, CI runner, container image and production deployment process may each use a separate Composer installation, so checking only the version on one machine can miss an affected copy elsewhere in the delivery pipeline.
The Fix Shipped Before the CVE Was Publicised
Composer released versions 2.10.3 and 2.2.30 on 27 August 2026. The 2.10.3 release notes describe the security change as validation of package binary paths against path traversal using symlinks and identify both GHSA-96h3-5x6v-m776 and CVE-2026-59944.
OSV records the GitHub-reviewed advisory as published on 2 October, while GitLab also lists the affected and fixed version ranges. The later public advisory date therefore does not mean the fix was released in October; patched Composer builds had already been available since August.
Projects on the current Composer line should update to at least 2.10.3. Environments intentionally remaining on the Composer 2.2 line should use at least 2.2.30. The Composer advisory states that upgrading is the only complete fix.
References
-
CVE-2026-59944: Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path, GitLab (2 October 2026)
-
-
-
