PT-2026-84464 · Composer · Composer
CVE-2026-84361
·
Published
2026-08-27
·
Updated
2026-09-09
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Composer versions 1.0 through 2.2.29
Composer versions 2.10.0 through 2.10.2
Description
Composer, a dependency manager for PHP, fails to validate the
source.url when source.type is set to perforce. A malicious package from a custom repository or an untrusted composer.lock file can specify an rsh: or jsh: P4PORT value. If the Perforce p4 client is installed, executing composer install or composer update (including the --prefer-source flag) causes the ComposerUtilPerforce function to pass the unvalidated address to p4, leading to the execution of local commands with the privileges of the user or CI account.Recommendations
Update to version 2.2.30 or later.
Update to version 2.10.3 or later.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Composer