CVE-2026-84361High▾ MidnightPoC availableComposer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
1 GitHub repo (last check)
Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\Util\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
composer/composer >= 2.3.0, < 2.10.3composer/composer >= 1.0, < 2.2.30Patched in:
composer/composer 2.10.3composer/composer 2.2.30Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59944Medium· 6.1Composer is a dependency Manager for the PHP language
CVE-2026-59947Medium· 4.7Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
CVE-2026-59946Medium· 6.1Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
CVE-2026-59948High· 7.0Composer: Arbitrary file write outside vendor via malicious transitive package name
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CVE-2024-51378Critical· 10.0getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…