OS Command Injection Affecting composer package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.41% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-COMPOSER-19501524
  • published3 Sept 2026
  • disclosed1 Sept 2026

Introduced: 1 Sep 2026

NewCVE-2026-84361  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

There is no fixed version for Debian:13 composer.

NVD Description

Note: Versions mentioned in the description apply only to the upstream composer package and not the composer package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\Util\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.

CVSS Base Scores

version 3.1