Supply Chain Sabotage: The Critical RCE Flaws Lurking in PHP Composer
ID: 8e83a99c-3f8e-58ef-9295-3810ad076215
STIX ID: report--8e83a99c-3f8e-58ef-9295-3810ad076215
Feed Name: securityonline.info
Researchers disclosed two Remote Command Injection flaws in Composer's Perforce handling (CVE-2026-40176 — CVSS 7.8, and CVE-2026-40261 — CVSS 8.8) that can lead to arbitrary shell execution from a malicious composer.json or compromised Composer repository; the second issue can be exploited even if Perforce is not installed. Composer maintainers released fixes in 2.2.27 (LTS) and 2.9.6 (mainline); recommended mitigations include upgrading immediately, preferring distribution installs (--prefer-dist), limiting trusted repositories, and inspecting composer.json before running Composer on untrusted projects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
