CVE-2026-40176

EUVD-2026-23118
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from the root composer.json or the composer config directory, so this cannot be exploited through composer.json files of packages installed as dependencies. Users are at risk if they run Composer commands on untrusted projects with attacker-supplied composer.json files. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline).
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 62.14%
Affected Products (NVD)
VendorProductVersion
getcomposercomposer
1.0.0 ≤
𝑥
≤ 2.2.26
getcomposercomposer
2.3.0 ≤
𝑥
≤ 2.9.5
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Hardened Images
2.9.7-1.hum1 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
composer
bookworm
2.5.5-1+deb12u5
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
2.10.2-1
fixed
sid
2.10.2-1
fixed
trixie
2.8.8-1+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
composer
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
composer
Amazon Linux 2023
0:2.9.7-1.amzn2023.0.1
fixed