CVE-2026-40261Patch(getcomposer / composer)

HIGHCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 13 mentions and remains active

Immediate actions

  • Patch getcomposer composer systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed. Unlike CVE-2026-40176, the source reference and url are provided as part of package metadata, meaning any compromised or malicious Composer repository can serve package metadata declaring perforce as a source type with malicious values. This vulnerability is exploitable when installing or updating dependencies from source, including the default behavior when installing dev-prefixed versions. This issue has been fixed in Composer 2.2.27 (2.2 LTS) and 2.9.6 (mainline). If developers are unable to immediately update, they can avoid installing dependencies from source by using --prefer-dist or the preferred-install: dist config setting, and only use trusted Composer repositories as a workaround.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • composer

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 28 mentions across 6 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 23 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 13 mentions (2026-04-15); latest day: 1
  • 28 total mentions across 6 days

Affected systems

Products
composer

Deep dive

Activity timeline28 mentions / 6d
0371013Mentions · 2026-04-14: 8Mentions · 2026-04-15: 13Mentions · 2026-04-16: 3Mentions · 2026-04-17: 2Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-16: 1Exploit Tool / Code · 2026-04-16: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-15: 1Patch / Workaround · 2026-04-14: 6Patch / Workaround · 2026-04-15: 7Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-14: 8Technical Details · 2026-04-15: 10Technical Details · 2026-04-16: 3Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-1404-1504-1604-1704-2204-23
Signal classification6 categories
Patch
1450.0%
Disclosure
725.0%
General
310.7%
Active Exploitation
27.1%
Exploit
13.6%
PoC
13.6%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-04-148
Active Exploitation1Disclosure2Exploit1Patch4
2026-04-1513
Active Exploitation1Disclosure4General1Patch7
2026-04-163
Disclosure1Patch1PoC1
2026-04-172
General2
2026-04-221
Patch1
2026-04-231
Patch1
Full discourse20 posts
  • Packagist@packagist
    Patch

    🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. No exploitation detected on http://Packagist.org and Private Packagist. #php #phpc #composerphp

    Post summary

    Composer released updates 2.9.6 and 2.2.27 to fix command‑injection vulnerabilities CVE-2026-40261 and CVE-2026-40176 in the Perforce driver, with no exploitation reported. Users are advised to run composer self‑update.

    25131143822.0K
    8.4K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    ⚠️ ALERT - Composer disclosed two command injection flaws (CVE-2026-40176 and CVE-2026-40261) with up to CVSS 8.8 severity. Malicious composer.json or crafted source refs can execute arbitrary commands—even without Perforce installed. 🔗 Read → https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.html

    Post summary

    Composer command injection vulnerabilities (CVE-2026-40176 and CVE-2026-40261) have been disclosed, enabling arbitrary command execution through malicious composer.json files or crafted source references, with severity up to CVSS 8.8.

    35471043021.6K
    1.7M followersView on X
  • Punyapal Shah | Laravel | PHP | Dev | OpenSource@MrPunyapal
    Patch

    🚨 Composer security alert Two command injection vulnerabilities found (CVE-2026-40176, CVE-2026-40261) via the Perforce driver. 👉 Update to 2.9.6 / 2.2.27 👉 Avoid untrusted composer.json #PHP #Laravel #Security #Composer https://t.co/A5ZCOZc10y

    Post summary

    The tweet announces command injection CVEs in Composer’s Perforce driver and urges users to update to 2.9.6 / 2.2.27 and avoid untrusted composer.json files.

    11003694.3K
    7.6K followersView on X
  • Saku0512@AraLab@Saku_0512_sec
    PoC

    https://www.cve.org/CVERecord?id=CVE-2026-40176 cve++ Composer(composer.json)におけるOSコマンドインジェクションの脆弱性 CVSS 8.7 High 最新版(2.9.6 / 2.2.27 LTS)への更新を推奨 poc https://github.com/Saku0512/CVE-2026-40176-poc わかりやすい記事 https://ai-heartland.com/news/news-composer-cve-2026-40261-perforce-rce/

    Post summary

    The text announces CVE-2026-40176, details an OS command injection in Composer, provides a PoC repository link, recommends updating to patched versions, and gives technical severity data.

    01002451.4K
    335 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical Remote Command Injection flaws in PHP Composer's Perforce integration (CVE-2026-40176 & CVE-2026-40261) could lead to full system compromise. Patch now. #PHPSecurity #Cybersecurity #SupplyChainAttack #InfoSec #Composer #CVE #WebDevelopment https://securityonline.info/composer-perforce-remote-command-injection-vulnerability/ https://t.co/9rEbaWZfrB

    Post summary

    The tweet highlights remote command injection vulnerabilities in PHP Composer’s Perforce integration, urgently urging users to apply patches to prevent full system compromise.

    0602141.0K
    12.3K followersView on X
  • IT-Connect.fr@ITConnect_fr
    General

    🚨 Alerte sécurité PHP Composer 🛡️ Un risque pour les environnements de développement et de production à cause de ces deux failles : CVE-2026-40176 et CVE-2026-40261. 👉 Vous avez vérifié votre version ? https://www.it-connect.fr/php-composer-ces-deux-failles-ouvrent-la-porte-a-lexecution-de-commande/ #Cybersécurité #PHP https://www.it-connect.fr/php-composer-ces-deux-failles-ouvrent-la-porte-a-lexecution-de-commande/

    Post summary

    Security alert identifies two CVEs affecting PHP Composer, but provides no PoC, exploit, patch, or technical details.

    020103874
    11.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - PHP Composer command injection via Perforce (CVE-2026-40176, CVE-2026-40261) Unsanitized sourceReference / sourceUrl in package metadata can lead to command injection via Perforce operations. 👉 Update to 2.2.27 / 2.9.6 to mitigate https://t.co/LZICacAGJ4

    Post summary

    CVE-2026-40176 and CVE-2026-40261 expose PHP Composer to command injection via unsanitized sourceReference/sourceUrl in Perforce; updates 2.2.27 and 2.9.6 mitigate the issue.

    00080158
    229 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-composer モジュール更新情報 2.9.7-1 https://kusanagi.tokyo/releases/24337/ KUSANAGI9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 composer 2.9.7-1 この更新には脆弱性(CVE-2026-40261, CVE-2026-40176)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf update Security Edit...

    Post summary

    The notice announces a kusanagi composer module update that addresses CVE-2026-40261 and CVE-2026-40176, installable via dnf update.

    01010116
    200 followersView on X
  • iototsecnews@iototsecnews
    Patch

    PHP Composer の脆弱性 CVE-2026-40176/40261 が FIX:任意のコマンド実行の可能性 https://iototsecnews.jp/2026/04/15/new-php-composer-vulnerability-let-attackers-execute-arbitrary-commands/ 今回の緊急アップデートにおける主な原因は、PHP の依存関係管理ツールである Composer が、外部のプログラム (Perforce) とインタラクションのための命令を作る際も、文字の処理 (エスケープ) が不十分だったことにあります。具体的には脆弱性 CVE-2026-40176/CVE-2026-40261 により、設定ファイルである “composer.json” やパッケージの管理データに悪意の記号を混ぜることで、開発者のコンピュータ上でプログラムを実行させることが可能になっていました。特に、Perforce というソフトウェアをインストールしていなくても、Composer 経由で攻撃が成立してしまう点が極めて危険です。ご利用のチームは、ご注意ください。 #CVE202640176 #CVE202640261 #PHPComposer #Vulnerability

    Post summary

    The article reports an urgent fix for Composer CVE-2026-40176/40261, outlining that improper escaping in composer.json can lead to arbitrary command execution, and urges teams to apply available patches.

    01000144
    486 followersView on X
  • カック@kakakakakku
    General

    Composer に CVE 出てるから見てる👀 Composer 2.9.6: Perforce Driver Command Injection Vulnerabilities (CVE-2026-40261, CVE-2026-40176) https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/

    Post summary

    The user is reviewing details of CVE-2026-40261 and CVE-2026-40176 affecting Composer 2.9.6, which are command injection flaws, but no PoC, exploit, or patch information is supplied.

    00010436
    3.5K followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Patch

    🚨PHP Composerに緊急脆弱性! 悪意あるコードが実行される危険性あり。Perforce VCSドライバにコマンドインジェクションの脆弱性(CVE-2026-40176, CVE-2026-40261)。今すぐパッチを適用して対策を! Composer使ってる?アップデート忘れずに!#PHP #セキュリティ https://t.co/Fi1w5FKqqE

    Post summary

    Urgent vulnerability in PHP Composer’s Perforce VCS driver with command injection (CVE-2026-40176, CVE-2026-40261) announced, urging immediate patching.

    10000229
    267 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited command injection flaws in PHP Composer's Perforce driver (CVE-2026-40176, CVE-2026-40261) to execute arbitrary commands and escalate privileges. Runtime segmentation helps contain post-compromise lateral movement in developer environments. #DevSecOps :link: Full breakdown: https://aviatrix.ai/threat-research-center/php-composer-2026-perforce-driver-command-injection

    Post summary

    The tweet reports real‑world exploitation of command injection flaws in PHP Composer’s Perforce driver (CVE‑2026‑40176, CVE‑2026‑40261), citing a detailed breakdown at the provided link.

    0001073
    1.9K followersView on X
  • セキュリティ系行政書士feat.著作権の遠藤さん@beansgyosei
    Patch

    ComposerのPerforce VCSドライバーに複数の任意のコマンド実行につながる脆弱性 Composer 2.9.6 fixes Perforce Driver Command Injection Vulnerabilities (CVE-2026-40261, CVE-2026-40176) https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/

    Post summary

    The post announces that Composer 2.9.6 addresses two command‑injection CVEs (CVE‑2026‑40261, CVE‑2026‑40176) in its Perforce driver, indicating a vendor patch release.

    0000077
    1.0K followersView on X
  • Franck MAURICE@FRC_MAURICE
    General

    @BoardGameArena Is it cause by CVE-2026-40176 et CVE-2026-40261. ?

    Post summary

    The tweet is a simple query asking if an issue is caused by two specific CVEs, with no further detail or actionable information.

    000001.1K
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40261 Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() … https://www.cve.org/CVERecord?id=CVE-2026-40261

    Post summary

    This entry announces a command injection vulnerability in Composer’s Perforce::syncCodeBase() affecting versions 1.0‑2.2.26 and 2.3‑2.9.5, with no PoC, exploit, or patch details provided.

    00000109
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40261 Command Injection in Composer Dependency Manager Versions 1.0-2.2.26 and 2.3-2.9.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40261

    Post summary

    The text announces a command injection vulnerability (CVE‑2026‑40261) in Composer Dependency Manager affecting specific version ranges, but does not provide details on exploitation or mitigation.

    0000048
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Composer (CVE-2026-40261) https://vuldb.com/vuln/357668/cti

    Post summary

    Detection of increased activity against Composer for CVE-2026-40261 suggests it is actively exploited in the wild.

    0000065
    2.1K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-40261 Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-40261 #HP #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑40261 is a high‑severity command injection flaw affecting several Composer versions, with a CVSS score of 8.8. The announcement lists affected releases and links to a full analysis but provides no exploit code, tool, or patch details.

    000002
    145 followersView on X
  • DevOps Daily@thedevopsdaily
    Disclosure

    📝 Two Composer Command Injection Flaws Let Attackers Run Arbitrary Code - Even Without Perforce CVE-2026-40176 and CVE-2026-40261 affect all Composer 2.x versions. A malicious composer.json or cra https://devops-daily.com/posts/composer-command-injection-cve-2026 #DevOps #Security

    Post summary

    The post announces two Composer 2.x command injection flaws that enable arbitrary code execution via malicious composer.json files.

    0000058
    92 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-comoser Module Update 2.9.7-1 https://kusanagi.tokyo/en/releases/24338/ KUSANAGI9 modules have been updated. The updated modules are as follows: composer 2.9.7-1 This update includes support for vulnerability(CVE-2026-40261, CVE-2026-40176). The module update can be applied...

    Post summary

    The composer module update 2.9.7‑1 includes fixes for CVE‑2026‑40261 and CVE‑2026‑40176, indicating a patch has been applied; no PoC, exploit tool, or evidence of active exploitation is reported.

    0000056
    200 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetcomposercomposer---

Explore more