New PHP Composer Vulnerability Let Attackers Execute Arbitrary Commands
ID: 8f0c534a-d92c-57e5-9d5a-890a2fced1a3
STIX ID: report--8f0c534a-d92c-57e5-9d5a-890a2fced1a3
Feed Name: cybersecurityNews.com
PHP Composer released urgent updates for two critical command-injection vulnerabilities in its Perforce VCS handling and source-reference escaping (CVE-2026-40176 and CVE-2026-40261) that can enable arbitrary command execution via malicious composer.json or package metadata; users should upgrade to Composer 2.9.6 or 2.2.27 and apply recommended mitigations (prefer-dist, inspect composer.json, use trusted repositories); Packagist has disabled Perforce source metadata and scans found no evidence of exploitation prior to disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
