logo

Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)

ID: cfe9d1b4-d4a6-5f01-ad68-64e803e21c9e

STIX ID: report--cfe9d1b4-d4a6-5f01-ad68-64e803e21c9e

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Ddos

...
...

Composer advisory for CVE-2026-45793: a validation bug caused Composer to reject hyphen-containing GitHub tokens and include the full token in an error message, which allowed those tokens to be written to CI/CD logs (valid for up to 6 hours on GitHub-hosted runners and up to 24 hours on self-hosted runners). Composer released fixes (update to 2.9.8 or 2.2.28), and the advisory recommends immediate updates, auditing Action logs for the "invalid characters" error, rotating any exposed tokens, and disabling Composer runs until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.