PT-2026-40868 · Composer · Composer

Published

2026-05-14

·

Updated

2026-05-14

·

CVE-2026-45793

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Composer versions prior to 2.9.8
Description A validation error in Composer causes GitHub tokens to be leaked into CI/CD logs.
Recommendations Update to version 2.9.8. Audit GitHub Action logs for leaked tokens.

Related Identifiers

CVE-2026-45793

Affected Products

Composer