composer/composer
GHSA-rvx4-ffvw-m9q3
Packagistmalware9/8/2026
Description
Composer arbitrary command execution via a malicious package's Perforce source URL
References (7)
https://github.com/composer/composer/security/advisories/GHSA-rvx4-ffvw-m9q3github_advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-84361github_advisoryhttps://github.com/composer/composer/commit/0aac50528e83ed635cf788333635897469440220github_advisoryhttps://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521afgithub_advisoryhttps://github.com/composer/composergithub_advisoryhttps://github.com/composer/composer/releases/tag/2.10.3github_advisoryhttps://github.com/composer/composer/releases/tag/2.2.30github_advisory
Details
EcosystemPackagist
Attack Typemalware
Published9/8/2026
Affected Versions
1.0
Related CVEs
Aliases
CVE-2026-84361
Quick Actions