logo

New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released

ID: 64f624f7-2636-54a4-a7c9-ea820a91b96c

STIX ID: report--64f624f7-2636-54a4-a7c9-ea820a91b96c

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-04-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Two high-severity command-injection vulnerabilities (CVE-2026-40176, CVE-2026-40261) were disclosed in Composer's Perforce VCS driver that can enable arbitrary command execution. Affected versions are fixed in Composer 2.9.6 and 2.2.27; Packagist disabled Perforce metadata and users are advised to update immediately, inspect composer.json entries, and avoid untrusted repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.