PT-2026-32622 · Packagist · Composer/Composer

Published

2026-04-14

·

Updated

2026-04-14

·

CVE-2026-40261

CVSS v3.1

8.8

High

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
⚠️ ALERT - Composer disclosed two command injection flaws (CVE-2026-40176 and CVE-2026-40261) with up to CVSS 8.8 severity.
Malicious composer.json or crafted source refs can execute arbitrary commands—even without Perforce installed.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-40261
GHSA-GQW4-4W2P-838Q

Affected Products

Composer/Composer