Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

fstec логотип

BDU:2026-05521

4 месяца назад

Уязвимость метода Perforce::generateP4Command() менеджера зависимостей для PHP Composer, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-40176

4 месяца назад

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from the root composer.json or the composer config directory, so this cannot be exploited through composer.json files of packages installed as dependencies. Users are at risk if they run Composer commands on untrusted projects with attacker-supplied composer.json files. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline).

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-40176

4 месяца назад

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from the root composer.json or the composer config directory, so this cannot be exploited through composer.json files of packages installed as dependencies. Users are at risk if they run Composer commands on untrusted projects with attacker-supplied composer.json files. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline).

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-40176

4 месяца назад

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from the root composer.json or the composer config directory, so this cannot be exploited through composer.json files of packages installed as dependencies. Users are at risk if they run Composer commands on untrusted projects with attacker-supplied composer.json files. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline).

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-40176

4 месяца назад

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-wg36-wvj6-r67p

4 месяца назад

Composer has a command injection via malicious perforce repository

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1784-1

3 месяца назад

Security update for php-composer2

EPSS: Низкий
fstec логотип

BDU:2026-05574

4 месяца назад

Уязвимость функции syncCodeBase() средства управления зависимостями PHP-пакетов Composer, позволяющая нарушителю внедрить произвольные команды

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20670-1

3 месяца назад

Security update for php-composer2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21520-1

8 дней назад

Security update for php-composer2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1970-1

3 месяца назад

Security update for php-composer2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3105-1

25 дней назад

Security update for php-composer2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-05521

Уязвимость метода Perforce::generateP4Command() менеджера зависимостей для PHP Composer, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.8
1%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-40176

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from the root composer.json or the composer config directory, so this cannot be exploited through composer.json files of packages installed as dependencies. Users are at risk if they run Composer commands on untrusted projects with attacker-supplied composer.json files. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline).

CVSS3: 7.8
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-40176

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from the root composer.json or the composer config directory, so this cannot be exploited through composer.json files of packages installed as dependencies. Users are at risk if they run Composer commands on untrusted projects with attacker-supplied composer.json files. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline).

CVSS3: 7.8
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-40176

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from the root composer.json or the composer config directory, so this cannot be exploited through composer.json files of packages installed as dependencies. Users are at risk if they run Composer commands on untrusted projects with attacker-supplied composer.json files. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline).

CVSS3: 7.8
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-40176

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 ...

CVSS3: 7.8
1%
Низкий
4 месяца назад
github логотип
GHSA-wg36-wvj6-r67p

Composer has a command injection via malicious perforce repository

CVSS3: 7.8
1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1784-1

Security update for php-composer2

3 месяца назад
fstec логотип
BDU:2026-05574

Уязвимость функции syncCodeBase() средства управления зависимостями PHP-пакетов Composer, позволяющая нарушителю внедрить произвольные команды

CVSS3: 8.8
2%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20670-1

Security update for php-composer2

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21520-1

Security update for php-composer2

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:1970-1

Security update for php-composer2

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3105-1

Security update for php-composer2

25 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.