PHP Composer flaws enable remote command execution via Perforce VCS
ID: e96eb0a1-29cb-546c-b725-99af8e112f2b
STIX ID: report--e96eb0a1-29cb-546c-b725-99af8e112f2b
Feed Name: Security Affairs
Two high-severity command‑injection vulnerabilities in PHP Composer's Perforce VCS driver (CVE-2026-40176 CVSS 7.8 and CVE-2026-40261 CVSS 8.8) can allow arbitrary command execution via malicious composer.json repository configs or crafted source references; users should upgrade to Composer 2.9.6 or 2.2.27 (LTS), avoid installing dependencies from source (prefer-dist), and verify repository metadata—Packagist scans reported no exploitation and Perforce metadata publishing/VCS driver were disabled as a precaution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
