Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
ID: cfe9d1b4-d4a6-5f01-ad68-64e803e21c9e
STIX ID: report--cfe9d1b4-d4a6-5f01-ad68-64e803e21c9e
Feed Name: securityonline.info
Composer advisory for CVE-2026-45793: a validation bug caused Composer to reject hyphen-containing GitHub tokens and include the full token in an error message, which allowed those tokens to be written to CI/CD logs (valid for up to 6 hours on GitHub-hosted runners and up to 24 hours on self-hosted runners). Composer released fixes (update to 2.9.8 or 2.2.28), and the advisory recommends immediate updates, auditing Action logs for the "invalid characters" error, rotating any exposed tokens, and disabling Composer runs until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
