Threat Advisory

Composer Flaw Executes Arbitrary Commands via Malicious Perforce Source URL

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high severity vulnerability affecting composer/composer versions >= 2.3.0, < 2.10.3 affecting composer/composer versions >= 1.0, < 2.2.30, identified as CVE-2026-84361 with a CVSS score of 7.7, exists in Composer that allows arbitrary command execution via a malicious package's Perforce source URL. This flaw is caused by Composer passing a package's Perforce source address to the p4 CLI client without validating it, enabling remote code execution with user or CI account privileges when running composer install or update. The vulnerability affects users who have the Perforce p4 command line client installed and on their system path, rely on custom or untrusted Composer repositories, and select source installs for packages that have no dist artifact or use --prefer-source. Most affected are developer workstations or CI images with Perforce tooling installed, pulling packages from compromised private or third-party Composer repositories.

RECOMMENDATION:

We recommend you to update Composer to version 2.10.3 or 2.2.30.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high severity vulnerability affecting composer/composer versions >= 2.3.0, < 2.10.3 affecting composer/composer versions >= 1.0, < 2.2.30, identified as CVE-2026-84361 with a CVSS score of 7.7, exists in Composer that allows arbitrary command execution via a malicious package's Perforce source URL. This flaw is caused by Composer passing a package's Perforce source address to the p4 CLI client without validating it, enabling remote code execution with user or CI account privileges when running composer install or update. The vulnerability affects users who have the Perforce p4 command line client installed and on their system path, rely on custom or untrusted Composer repositories, and select source installs for packages that have no dist artifact or use --prefer-source. Most affected are developer workstations or CI images with Perforce tooling installed, pulling packages from compromised private or third-party Composer repositories.

RECOMMENDATION:

We recommend you to update Composer to version 2.10.3 or 2.2.30.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu