PT-2026-84464 · Composer · Composer

CVE-2026-84361

·

Published

2026-08-27

·

Updated

2026-09-09

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Composer versions 1.0 through 2.2.29 Composer versions 2.10.0 through 2.10.2
Description Composer, a dependency manager for PHP, fails to validate the source.url when source.type is set to perforce. A malicious package from a custom repository or an untrusted composer.lock file can specify an rsh: or jsh: P4PORT value. If the Perforce p4 client is installed, executing composer install or composer update (including the --prefer-source flag) causes the ComposerUtilPerforce function to pass the unvalidated address to p4, leading to the execution of local commands with the privileges of the user or CI account.
Recommendations Update to version 2.2.30 or later. Update to version 2.10.3 or later.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14209
BIT-COMPOSER-2026-84361
CVE-2026-84361
GHSA-RVX4-FFVW-M9Q3
OPENSUSE-SU-2026:11689-1
OPENSUSE-SU-2026:21778-1

Affected Products

Composer