logo

New PHP Composer Vulnerability Let Attackers Execute Arbitrary Commands

ID: 8f0c534a-d92c-57e5-9d5a-890a2fced1a3

STIX ID: report--8f0c534a-d92c-57e5-9d5a-890a2fced1a3

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-15

Date Updated: 2026-04-21

Author: Abinaya

...
...

PHP Composer released urgent updates for two critical command-injection vulnerabilities in its Perforce VCS handling and source-reference escaping (CVE-2026-40176 and CVE-2026-40261) that can enable arbitrary command execution via malicious composer.json or package metadata; users should upgrade to Composer 2.9.6 or 2.2.27 and apply recommended mitigations (prefer-dist, inspect composer.json, use trusted repositories); Packagist has disabled Perforce source metadata and scans found no evidence of exploitation prior to disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.