CVE-2026-40176Disclosure(getcomposer / composer)

HIGHCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch getcomposer composer systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the user running Composer, even if Perforce is not installed. VCS repositories are only loaded from the root composer.json or the composer config directory, so this cannot be exploited through composer.json files of packages installed as dependencies. Users are at risk if they run Composer commands on untrusted projects with attacker-supplied composer.json files. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline).

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • composer

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 29 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 27 signals
  • Disclosure: 15 classified signals
  • Peaked 4d ago at 12 mentions (2026-04-15); latest day: 1
  • 29 total mentions across 6 days

Affected systems

Products
composer

Deep dive

Activity timeline29 mentions / 6d
036912Mentions · 2026-04-14: 9Mentions · 2026-04-15: 12Mentions · 2026-04-16: 4Mentions · 2026-04-17: 2Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-16: 1Exploit Tool / Code · 2026-04-16: 1Active Exploitation · 2026-04-14: 1Patch / Workaround · 2026-04-14: 7Patch / Workaround · 2026-04-15: 7Patch / Workaround · 2026-04-16: 3Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-14: 9Technical Details · 2026-04-15: 11Technical Details · 2026-04-16: 4Technical Details · 2026-04-17: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-1404-1504-1604-1704-2204-23
Signal classification4 categories
Disclosure
1551.7%
Patch
1241.4%
Active Exploitation
13.4%
General
13.4%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-04-149
Active Exploitation1Disclosure6Patch2
2026-04-1512
Disclosure6Patch6
2026-04-164
Disclosure1Patch3
2026-04-172
Disclosure1General1
2026-04-221
Patch1
2026-04-231
Disclosure1
Full discourse20 posts
  • Packagist@packagist
    Patch

    🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. No exploitation detected on http://Packagist.org and Private Packagist. #php #phpc #composerphp

    Post summary

    Composer announced new releases that patch command injection vulnerabilities CVE-2026-40261 and CVE-2026-40176; no exploitation has been detected and users are encouraged to update immediately.

    25131143822.0K
    8.4K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    ⚠️ ALERT - Composer disclosed two command injection flaws (CVE-2026-40176 and CVE-2026-40261) with up to CVSS 8.8 severity. Malicious composer.json or crafted source refs can execute arbitrary commands—even without Perforce installed. 🔗 Read → https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.html

    Post summary

    Composer has disclosed two command injection flaws (CVE-2026-40176 and CVE-2026-40261) with CVSS scores up to 8.8, allowing arbitrary command execution via malicious composer.json or crafted source references.

    35471043021.6K
    1.7M followersView on X
  • Punyapal Shah | Laravel | PHP | Dev | OpenSource@MrPunyapal
    Patch

    🚨 Composer security alert Two command injection vulnerabilities found (CVE-2026-40176, CVE-2026-40261) via the Perforce driver. 👉 Update to 2.9.6 / 2.2.27 👉 Avoid untrusted composer.json #PHP #Laravel #Security #Composer https://t.co/A5ZCOZc10y

    Post summary

    Two command injection vulnerabilities in Composer’s Perforce driver have been disclosed; users are advised to upgrade to version 2.9.6 or 2.2.27 and avoid using untrusted composer.json files.

    11003694.3K
    7.6K followersView on X
  • Saku0512@AraLab@Saku_0512_sec
    Patch

    https://www.cve.org/CVERecord?id=CVE-2026-40176 cve++ Composer(composer.json)におけるOSコマンドインジェクションの脆弱性 CVSS 8.7 High 最新版(2.9.6 / 2.2.27 LTS)への更新を推奨 poc https://github.com/Saku0512/CVE-2026-40176-poc わかりやすい記事 https://ai-heartland.com/news/news-composer-cve-2026-40261-perforce-rce/

    Post summary

    CVE‑2026‑40176 is an OS command injection in Composer with a CVSS of 8.7; a PoC exists and updating to the latest Composer versions is recommended.

    01002451.4K
    335 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical Remote Command Injection flaws in PHP Composer's Perforce integration (CVE-2026-40176 & CVE-2026-40261) could lead to full system compromise. Patch now. #PHPSecurity #Cybersecurity #SupplyChainAttack #InfoSec #Composer #CVE #WebDevelopment https://securityonline.info/composer-perforce-remote-command-injection-vulnerability/ https://t.co/9rEbaWZfrB

    Post summary

    The post highlights critical remote command injection vulnerabilities in PHP Composer’s Perforce integration (CVE-2026-40176 & CVE-2026-40261) and urges users to apply the available patches immediately.

    0602141.0K
    12.3K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    🚨 Alerte sécurité PHP Composer 🛡️ Un risque pour les environnements de développement et de production à cause de ces deux failles : CVE-2026-40176 et CVE-2026-40261. 👉 Vous avez vérifié votre version ? https://www.it-connect.fr/php-composer-ces-deux-failles-ouvrent-la-porte-a-lexecution-de-commande/ #Cybersécurité #PHP https://www.it-connect.fr/php-composer-ces-deux-failles-ouvrent-la-porte-a-lexecution-de-commande/

    Post summary

    The tweet announces two new CVE vulnerabilities in PHP Composer that allow command execution, directing readers to an article for more details, but it does not provide PoC, exploit code, or patch information.

    020103874
    11.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - PHP Composer command injection via Perforce (CVE-2026-40176, CVE-2026-40261) Unsanitized sourceReference / sourceUrl in package metadata can lead to command injection via Perforce operations. 👉 Update to 2.2.27 / 2.9.6 to mitigate https://t.co/LZICacAGJ4

    Post summary

    The post announces high‑severity command injection vulnerabilities in PHP Composer via Perforce and provides the recommended version updates to mitigate the issue.

    00080158
    229 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-composer モジュール更新情報 2.9.7-1 https://kusanagi.tokyo/releases/24337/ KUSANAGI9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 composer 2.9.7-1 この更新には脆弱性(CVE-2026-40261, CVE-2026-40176)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf update Security Edit...

    Post summary

    The release notes announce a module update that patches CVE‑2026‑40261 and CVE‑2026‑40176, without mentioning any PoC, exploit, or active exploitation.

    01010116
    200 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    PHP Composer の脆弱性 CVE-2026-40176/40261 が FIX:任意のコマンド実行の可能性 https://iototsecnews.jp/2026/04/15/new-php-composer-vulnerability-let-attackers-execute-arbitrary-commands/ 今回の緊急アップデートにおける主な原因は、PHP の依存関係管理ツールである Composer が、外部のプログラム (Perforce) とインタラクションのための命令を作る際も、文字の処理 (エスケープ) が不十分だったことにあります。具体的には脆弱性 CVE-2026-40176/CVE-2026-40261 により、設定ファイルである “composer.json” やパッケージの管理データに悪意の記号を混ぜることで、開発者のコンピュータ上でプログラムを実行させることが可能になっていました。特に、Perforce というソフトウェアをインストールしていなくても、Composer 経由で攻撃が成立してしまう点が極めて危険です。ご利用のチームは、ご注意ください。 #CVE202640176 #CVE202640261 #PHPComposer #Vulnerability

    Post summary

    The post announces a critical Composer vulnerability (CVE‑2026‑40176/40261) that permits arbitrary command execution through crafted composer.json files, but offers no PoC, exploit code, active exploitation evidence, or patch details.

    01000144
    486 followersView on X
  • カック@kakakakakku
    Disclosure

    Composer に CVE 出てるから見てる👀 Composer 2.9.6: Perforce Driver Command Injection Vulnerabilities (CVE-2026-40261, CVE-2026-40176) https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/

    Post summary

    The post shares a blog link discussing Composer 2.9.6 vulnerabilities that allow command injection via the Perforce Driver (CVE-2026-40261 and CVE-2026-40176).

    00010436
    3.5K followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Patch

    🚨PHP Composerに緊急脆弱性! 悪意あるコードが実行される危険性あり。Perforce VCSドライバにコマンドインジェクションの脆弱性(CVE-2026-40176, CVE-2026-40261)。今すぐパッチを適用して対策を! Composer使ってる?アップデート忘れずに!#PHP #セキュリティ https://t.co/Fi1w5FKqqE

    Post summary

    The tweet announces command injection vulnerabilities (CVE-2026-40176, CVE-2026-40261) in PHP Composer's Perforce VCS driver and urges users to apply the available patch immediately.

    10000229
    267 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited command injection flaws in PHP Composer's Perforce driver (CVE-2026-40176, CVE-2026-40261) to execute arbitrary commands and escalate privileges. Runtime segmentation helps contain post-compromise lateral movement in developer environments. #DevSecOps :link: Full breakdown: https://aviatrix.ai/threat-research-center/php-composer-2026-perforce-driver-command-injection

    Post summary

    The post reports that attackers exploited CVE-2026-40176 and CVE-2026-40261 via command injection to run arbitrary code and gain elevated privileges, offering runtime segmentation as a containment mitigation.

    0001073
    1.9K followersView on X
  • セキュリティ系行政書士feat.著作権の遠藤さん@beansgyosei
    Patch

    ComposerのPerforce VCSドライバーに複数の任意のコマンド実行につながる脆弱性 Composer 2.9.6 fixes Perforce Driver Command Injection Vulnerabilities (CVE-2026-40261, CVE-2026-40176) https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/

    Post summary

    The post announces the new Composer 2.9.6 release which patches the Perforce VCS driver command injection CVEs, with no mention of PoC, exploits, or active attacks.

    0000077
    1.0K followersView on X
  • Franck MAURICE@FRC_MAURICE
    General

    @BoardGameArena Is it cause by CVE-2026-40176 et CVE-2026-40261. ?

    Post summary

    The tweet merely asks whether a game issue is caused by the listed CVEs, without providing any supporting technical detail or evidence.

    000001.1K
    10 followersView on X
  • Technoholic.me@technoholic_me
    Patch

    Two critical vulnerabilities in Composer, a PHP package manager, could allow command execution via Perforce VCS driver. Update immediately to patch CVE-2026-40176 and more. https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.html

    Post summary

    The post highlights two critical Composer vulnerabilities that enable command execution through the Perforce driver and urges users to patch CVE‑2026‑40176 immediately.

    0000034
    159 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40176 Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Comma… https://www.cve.org/CVERecord?id=CVE-2026-40176

    Post summary

    The text announces a CVE-2026-40176 command injection vulnerability in Composer’s Perforce::generateP4Comma, listing affected version ranges and linking to the CVE record.

    00000115
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40176 Command Injection in Composer Perforce VCS Repository Handler Versions 1.0-2.2.26 and 2.3-2.9.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40176

    Post summary

    The text announces a new command injection vulnerability in Composer Perforce VCS Repository Handler, listing affected versions but providing no PoC, exploitation, patch, or mitigation details.

    0000056
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-40176 Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection… CVSS 7.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-40176 #HP #CyberSecurity #InfoSec

    Post summary

    The vulnerability CVE‑2026‑40176 in Composer (PHP dependency manager) is a command injection flaw with CVSS 7.8. The post provides technical details and a link to analysis but does not mention a PoC, exploit, active exploitation, or patch.

    000003
    145 followersView on X
  • Daily Security Review@securitydailyr
    Disclosure

    Two critical command injection vulnerabilities, CVE-2026-40176 and CVE-2026-40177, have been found in Composer’s Perforce VCS driver—putting countless PHP applications at risk. Learn more: https://dailysecurityreview.com/resources/critical-security-flaws-in-composer-put-php-applications-at-risk/ https://t.co/9zivfP1lZf

    Post summary

    The post announces that two critical command injection vulnerabilities (CVE‑2026‑40176 and CVE‑2026‑40177) have been discovered in Composer’s Perforce VCS driver, potentially affecting many PHP applications, and directs readers to a link for additional information.

    0000038
    110 followersView on X
  • DevOps Daily@thedevopsdaily
    Disclosure

    📝 Two Composer Command Injection Flaws Let Attackers Run Arbitrary Code - Even Without Perforce CVE-2026-40176 and CVE-2026-40261 affect all Composer 2.x versions. A malicious composer.json or cra https://devops-daily.com/posts/composer-command-injection-cve-2026 #DevOps #Security

    Post summary

    This post announces two command‑injection CVEs (CVE‑2026‑40176, CVE‑2026‑40261) affecting Composer 2.x, allowing arbitrary code execution, without detailing exploits or patches.

    0000058
    92 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetcomposercomposer---

Explore more