๐Ÿ” CVE Alert

CVE-2026-84361

UNKNOWN 0.0

Composer: Perforce source URL permits P4PORT `rsh:` command execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\Util\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.

CWE CWE-78
Vendor composer
Product composer
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for composer composer

Be the first to know when new unknown vulnerabilities affecting composer composer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

composer / composer
>= 1.0, < 2.2.30 >= 2.3.0, < 2.10.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/composer/composer/security/advisories/GHSA-rvx4-ffvw-m9q3 github.com: https://github.com/composer/composer/commit/0aac50528e83ed635cf788333635897469440220 github.com: https://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af github.com: https://github.com/composer/composer/releases/tag/2.10.3 github.com: https://github.com/composer/composer/releases/tag/2.2.30