Punyapal Shah | Laravel | PHP | Dev | OpenSource[verified]@MrPunyapalPatch
The tweet announces command injection CVEs in Composer’s Perforce driver and urges users to update to 2.9.6 / 2.2.27 and avoid untrusted composer.json files.
Upwind Security MDR[verified]@UpwindMDRPatch
CVE-2026-40176 and CVE-2026-40261 expose PHP Composer to command injection via unsanitized sourceReference/sourceUrl in Perforce; updates 2.2.27 and 2.9.6 mitigate the issue.
カック[verified]@kakakakakkuGeneral
The user is reviewing details of CVE-2026-40261 and CVE-2026-40176 affecting Composer 2.9.6, which are command injection flaws, but no PoC, exploit, or patch information is supplied.
motch | セキュリティ🛡️[verified]@motch_devPatch
Urgent vulnerability in PHP Composer’s Perforce VCS driver with command injection (CVE-2026-40176, CVE-2026-40261) announced, urging immediate patching.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The tweet reports real‑world exploitation of command injection flaws in PHP Composer’s Perforce driver (CVE‑2026‑40176, CVE‑2026‑40261), citing a detailed breakdown at the provided link.
セキュリティ系行政書士feat.著作権の遠藤さん[verified]@beansgyoseiPatch
The post announces that Composer 2.9.6 addresses two command‑injection CVEs (CVE‑2026‑40261, CVE‑2026‑40176) in its Perforce driver, indicating a vendor patch release.
Kaitan ID Security[verified]@KaitanSecurityDisclosure
CVE‑2026‑40261 is a high‑severity command injection flaw affecting several Composer versions, with a CVSS score of 8.8. The announcement lists affected releases and links to a full analysis but provides no exploit code, tool, or patch details.
Packagist@packagistPatch
Composer released updates 2.9.6 and 2.2.27 to fix command‑injection vulnerabilities CVE-2026-40261 and CVE-2026-40176 in the Perforce driver, with no exploitation reported. Users are advised to run composer self‑update.