Punyapal Shah | Laravel | PHP | Dev | OpenSource[verified]@MrPunyapalPatch
Two command injection vulnerabilities in Composer’s Perforce driver have been disclosed; users are advised to upgrade to version 2.9.6 or 2.2.27 and avoid using untrusted composer.json files.
Upwind Security MDR[verified]@UpwindMDRPatch
The post announces high‑severity command injection vulnerabilities in PHP Composer via Perforce and provides the recommended version updates to mitigate the issue.
カック[verified]@kakakakakkuDisclosure
The post shares a blog link discussing Composer 2.9.6 vulnerabilities that allow command injection via the Perforce Driver (CVE-2026-40261 and CVE-2026-40176).
motch | セキュリティ🛡️[verified]@motch_devPatch
The tweet announces command injection vulnerabilities (CVE-2026-40176, CVE-2026-40261) in PHP Composer's Perforce VCS driver and urges users to apply the available patch immediately.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The post reports that attackers exploited CVE-2026-40176 and CVE-2026-40261 via command injection to run arbitrary code and gain elevated privileges, offering runtime segmentation as a containment mitigation.
セキュリティ系行政書士feat.著作権の遠藤さん[verified]@beansgyoseiPatch
The post announces the new Composer 2.9.6 release which patches the Perforce VCS driver command injection CVEs, with no mention of PoC, exploits, or active attacks.
Kaitan ID Security[verified]@KaitanSecurityDisclosure
The vulnerability CVE‑2026‑40176 in Composer (PHP dependency manager) is a command injection flaw with CVSS 7.8. The post provides technical details and a link to analysis but does not mention a PoC, exploit, active exploitation, or patch.
Packagist@packagistPatch
Composer announced new releases that patch command injection vulnerabilities CVE-2026-40261 and CVE-2026-40176; no exploitation has been detected and users are encouraged to update immediately.