Back

HIGH

Composer has Command Injection via Malicious Perforce Reference

Published Apr 15, 2026

Description

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, including the default behavior when installing dev-prefixed versions. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline). If developers are unable to immediately update, they can avoid installing dependencies from source by using --prefer-dist or the preferred-install: dist config setting, and only use trusted Composer repositories as a workaround.

Affected products

Remediation

Red Hat statement

This issue can be exploited via any package served by a compromised or malicious Composer repository when installing or updating dependencies from source, including the default behavior when installing dev-prefixed versions. Exploitation results in arbitrary command execution. Due to these reasons, this flaw has been rated with an important severity.

Red Hat mitigation

To mitigate this issue, only run Composer commands on projects and dependencies from trusted sources. Also, use the '--prefer-dist' or the 'preferred-install: dist' configuration setting to prevent Composer from installing dependencies from source.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 15, 2026
Updated Jul 15, 2026
Reserved Apr 10, 2026
CISA Vulnrichment
Updated Apr 16, 2026
NVD
Status Modified
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Apr 15, 2026
ENISA EUVD
Assigner GitHub_M
Published Apr 15, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-23119 GHSA-GQW4-4W2P-838Q