Skip to content

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

Moderate severity GitHub Reviewed Published Jul 1, 2026 in composer/composer • Updated Jul 20, 2026

Package

composer composer/composer (Composer)

Affected versions

>= 2.3.0, < 2.10.2
>= 1.0.0, < 2.2.29

Patched versions

2.10.2
2.2.29

Description

Summary

When Composer is run with -vvv (debug verbosity), it could print a credential that was embedded directly in a repository or package URL, but not as a password, to its debug output. Composer already masked the password portion of such URLs, but the username portion was shown in clear text. Because GitHub and several other services support placing an access token in the username position of a URL (for example https://[token]@github.com/owner/repo), a token used that way could end up written to the verbose log in full.

This is an information disclosure issue. The credential is only ever exposed to whoever can already read Composer's debug output.

Am I affected?

You are potentially affected only if all of the following apply:

  • A credential is embedded inside a URL that Composer handles, e.g. in a repositories entry in composer.json, in a package dist/source URL - rather than being supplied through auth.json or the COMPOSER_AUTH environment variable.
  • The secret sits in the username slot of that URL (e.g. https://TOKEN@host/…). A normal username:password@host pair where the username is an ordinary account name did not expose the password, that was already masked.
  • Composer is run with -vvv (debug verbosity), and that output is retained or shared somewhere others can read it: public CI build logs, output pasted into an issue or chat, archived terminal sessions, and so on.

If you keep credentials in auth.json or environment variables, or you never run Composer at debug verbosity, you were not exposed.

The most realistic exposure is the documented pattern of embedding a GitHub Personal Access Token in a URL's username position on a machine (often CI) that captures verbose output.

Patched versions

The username is now masked the same way the password already was, so an embedded token no longer appears in verbose output (a short, non-secret prefix may be shown to aid debugging, but never the full value).

Fixed in Composer 2.10.2 and the 2.2.29.

Workarounds

There is no configuration setting that prevents outputting credentials while keeping normal behavior.

If you cannot upgrade right away, you can reduce exposure by:

  • Not running Composer with -vvv (debug verbosity) in environments where output is captured or shared.
  • Moving credentials out of URLs and into auth.json or COMPOSER_AUTH.
  • Scrubbing existing CI/build logs that may already contain a leaked token.

References

@Seldaek Seldaek published to composer/composer Jul 1, 2026
Published by the National Vulnerability Database Jul 8, 2026
Published to the GitHub Advisory Database Jul 20, 2026
Reviewed Jul 20, 2026
Last updated Jul 20, 2026

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Local
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS score

Exploit Prediction Scoring System (EPSS)

This score estimates the probability of this vulnerability being exploited within the next 30 days. Data provided by FIRST.
(1st percentile)

Weaknesses

Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file. Learn more on MITRE.

CVE ID

CVE-2026-59947

GHSA ID

GHSA-g6xq-892h-64w3

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.