Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-40261

4 месяца назад

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, incl...

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-40261

4 месяца назад

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, incl...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-40261

4 месяца назад

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, includi

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-40261

4 месяца назад

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-gqw4-4w2p-838q

4 месяца назад

Composer has a command injection via malicious perforce reference

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1784-1

3 месяца назад

Security update for php-composer2

EPSS: Низкий
fstec логотип

BDU:2026-05574

4 месяца назад

Уязвимость функции syncCodeBase() средства управления зависимостями PHP-пакетов Composer, позволяющая нарушителю внедрить произвольные команды

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-05521

4 месяца назад

Уязвимость метода Perforce::generateP4Command() менеджера зависимостей для PHP Composer, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20670-1

3 месяца назад

Security update for php-composer2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21520-1

8 дней назад

Security update for php-composer2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1970-1

3 месяца назад

Security update for php-composer2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3105-1

25 дней назад

Security update for php-composer2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-40261

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, incl...

CVSS3: 8.8
2%
Низкий
4 месяца назад
redhat логотип
CVE-2026-40261

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, incl...

CVSS3: 8.8
2%
Низкий
4 месяца назад
nvd логотип
CVE-2026-40261

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, includi

CVSS3: 8.8
2%
Низкий
4 месяца назад
debian логотип
CVE-2026-40261

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 ...

CVSS3: 8.8
2%
Низкий
4 месяца назад
github логотип
GHSA-gqw4-4w2p-838q

Composer has a command injection via malicious perforce reference

CVSS3: 8.8
2%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1784-1

Security update for php-composer2

3 месяца назад
fstec логотип
BDU:2026-05574

Уязвимость функции syncCodeBase() средства управления зависимостями PHP-пакетов Composer, позволяющая нарушителю внедрить произвольные команды

CVSS3: 8.8
2%
Низкий
4 месяца назад
fstec логотип
BDU:2026-05521

Уязвимость метода Perforce::generateP4Command() менеджера зависимостей для PHP Composer, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.8
1%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20670-1

Security update for php-composer2

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21520-1

Security update for php-composer2

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:1970-1

Security update for php-composer2

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3105-1

Security update for php-composer2

25 дней назад

Уязвимостей на страницу