CVE-2026-40176
composer composer, Red Hat Hardened Images
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from th...
- CVSS
- 7.8
- EPSS
- 1.06% 61.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.16