{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/composer--1.0--2.2.30/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-84361"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["composer (\u003e= 2.3.0, \u003c 2.10.3)","composer (\u003e= 1.0, \u003c 2.2.30)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","rce","php"],"_cs_type":"advisory","_cs_vendors":["Composer"],"content_html":"\u003cp\u003eComposer, a dependency manager for PHP, contains a vulnerability (CVE-2026-84361) that allows for arbitrary command execution when the Perforce (p4) CLI client is installed on the local system. The vulnerability exists because Composer fails to properly sanitize Perforce source URLs defined in package metadata before passing them to the \u003ccode\u003ep4\u003c/code\u003e command-line utility. Attackers who can control a package's \u003ccode\u003esource\u003c/code\u003e metadata - typically by utilizing private/third-party Composer repositories or untrusted \u003ccode\u003ecomposer.lock\u003c/code\u003e files - can provide specially crafted strings that the \u003ccode\u003ep4\u003c/code\u003e client interprets as local system commands rather than network connection endpoints.\u003c/p\u003e\n\u003cp\u003eThis flaw impacts developers and CI environments where the \u003ccode\u003ep4\u003c/code\u003e client is present on the system \u003ccode\u003ePATH\u003c/code\u003e. When \u003ccode\u003ecomposer install\u003c/code\u003e or \u003ccode\u003ecomposer update\u003c/code\u003e is executed against a malicious repository or lock file, the commands injected via the Perforce source URL are executed with the privileges of the user running the Composer process. This vulnerability was addressed in Composer versions 2.10.3 and 2.2.30.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full command execution on the target host, leading to system compromise, data theft, or lateral movement within build environments. The impact is highest in CI/CD pipelines where Composer processes untrusted dependencies, potentially compromising the entire development and deployment lifecycle. Organizations that do not use Perforce but have the \u003ccode\u003ep4\u003c/code\u003e CLI client installed on developer machines or build agents are also at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Composer to version 2.10.3 or 2.2.30 or later to ensure proper validation of Perforce source URLs.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, remove the \u003ccode\u003ep4\u003c/code\u003e binary from the system \u003ccode\u003ePATH\u003c/code\u003e of all environments running Composer.\u003c/li\u003e\n\u003cli\u003eAudit custom or third-party Composer repositories to ensure they are trusted and secure.\u003c/li\u003e\n\u003cli\u003eTreat \u003ccode\u003ecomposer.lock\u003c/code\u003e files obtained from external, untrusted sources with extreme caution.\u003c/li\u003e\n\u003cli\u003eRestrict the use of the \u003ccode\u003e--prefer-source\u003c/code\u003e flag in untrusted environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T21:50:03Z","date_published":"2026-09-08T21:50:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-composer-rce/","summary":"Composer versions before 2.10.3 and 2.2.30 are vulnerable to remote code execution when the Perforce CLI client is installed and a malicious package metadata source URL is processed (CVE-2026-84361).","title":"Arbitrary Command Execution in Composer via Malicious Perforce Source URLs","url":"https://feed.craftedsignal.io/briefs/2026-09-composer-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Composer (\u003e= 1.0, \u003c 2.2.30)","version":"https://jsonfeed.org/version/1.1"}