Composer has Command Injection via Malicious Perforce Reference
Published Apr 15, 2026
8.8
HIGHCVSS 3.1
EPSS 1.91%
Description
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, including the default behavior when installing dev-prefixed versions. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline). If developers are unable to immediately update, they can avoid installing dependencies from source by using --prefer-dist or the preferred-install: dist config setting, and only use trusted Composer repositories as a workaround.
Affected products
-
- Version >= 1.0.0, < 2.2.27StatusaffectedConstraints-
- Version >= 2.3.0, < 2.9.6StatusaffectedConstraints-
- Version
- ≥ 1.0.0 · ≤ 2.2.26
- ≥ 2.3.0 · ≤ 2.9.5
No data.
Red Hat Hardened Images
composer-main-2.9.7-1.hum1
Fixed · RHSA-2026:8165
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | composer-main-2.9.7-1.hum1 | Fixed | RHSA-2026:8165 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue can be exploited via any package served by a compromised or malicious Composer repository when installing or updating dependencies from source, including the default behavior when installing dev-prefixed versions. Exploitation results in arbitrary command execution. Due to these reasons, this flaw has been rated with an important severity.
Red Hat mitigation
To mitigate this issue, only run Composer commands on projects and dependencies from trusted sources. Also, use the '--prefer-dist' or the 'preferred-install: dist' configuration setting to prevent Composer from installing dependencies from source.
References (11)
- https://access.redhat.com/errata/RHSA-2026:8165
- https://access.redhat.com/security/cve/CVE-2026-40261 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2458841 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23119 Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/composer/composer/CVE-2026-40261.yaml
- https://github.com/advisories/GHSA-gqw4-4w2p-838q Advisory
- https://github.com/composer/composer/releases/tag/2.9.6 x_refsource_MISCRelease Notes
- https://github.com/composer/composer/security/advisories/GHSA-gqw4-4w2p-838q x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40261
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40261.json
- https://www.cve.org/CVERecord?id=CVE-2026-40261
Change history (0)
No recorded changes yet.