New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released
ID: 64f624f7-2636-54a4-a7c9-ea820a91b96c
STIX ID: report--64f624f7-2636-54a4-a7c9-ea820a91b96c
Feed Name: The Hacker News
Threat Score
Two high-severity command-injection vulnerabilities (CVE-2026-40176, CVE-2026-40261) were disclosed in Composer's Perforce VCS driver that can enable arbitrary command execution. Affected versions are fixed in Composer 2.9.6 and 2.2.27; Packagist disabled Perforce metadata and users are advised to update immediately, inspect composer.json entries, and avoid untrusted repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
