CPE
Composer versions before 2.10.3 and 2.2.30 are vulnerable to remote code execution when the Perforce CLI client is installed and a malicious package metadata source URL is processed (CVE-2026-84361).