logo

PHP Composer flaws enable remote command execution via Perforce VCS

ID: e96eb0a1-29cb-546c-b725-99af8e112f2b

STIX ID: report--e96eb0a1-29cb-546c-b725-99af8e112f2b

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Two high-severity command‑injection vulnerabilities in PHP Composer's Perforce VCS driver (CVE-2026-40176 CVSS 7.8 and CVE-2026-40261 CVSS 8.8) can allow arbitrary command execution via malicious composer.json repository configs or crafted source references; users should upgrade to Composer 2.9.6 or 2.2.27 (LTS), avoid installing dependencies from source (prefer-dist), and verify repository metadata—Packagist scans reported no exploitation and Perforce metadata publishing/VCS driver were disabled as a precaution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.