Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

composer — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting composer. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Composer is a dependency manager for PHP that enables developers to manage project libraries and their dependencies. Historically, it has been associated with vulnerabilities like remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often through compromised packages or insecure configurations. Notable security characteristics include its extensive package repository and automatic dependency resolution, which can introduce risks if not properly monitored. Major incidents include supply chain attacks where malicious code was injected into popular packages, leading to widespread exploitation. The tool's widespread adoption in PHP ecosystems makes it a critical component requiring robust security practices to mitigate potential threats from its package ecosystem.

Found 16 results / 17 Clear Filters
Top products by composer: composer windows-setup
CVE ID Title CVSS Severity Published
CVE-2026-59944 Composer: CVE-2026-59946 fix bypass via symlinked package bin path — composer CWE-22 6.1 Medium 2026-09-16
CVE-2026-84361 Composer: Perforce source URL permits P4PORT `rsh:` command execution — composer CWE-78 7.7 High 2026-09-01
CVE-2026-45793 Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs — composer CWE-200 7.5 High 2026-07-15
CVE-2026-59947 Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure) — composer CWE-532 4.7 Medium 2026-07-08
CVE-2026-59948 Composer: Arbitrary file write outside vendor via malicious transitive package name — composer CWE-22 7.0 High 2026-07-08
CVE-2026-59946 Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files — composer CWE-22 6.1 Medium 2026-07-08
CVE-2026-40261 Composer has Command Injection via Malicious Perforce Reference — composer CWE-78 8.8 High 2026-04-15
CVE-2026-40176 Composer is vulnerable to Command Injection via Malicious Perforce Repository — composer CWE-20 7.8 High 2026-04-15
CVE-2025-67746 Composer vulnerable to ANSI sequence injection — composer CWE-74 8.1 - 2025-12-30
CVE-2024-35242 Composer vulnerable to command injection via malicious git/hg branch names — composer CWE-77 8.8 High 2024-06-10
CVE-2024-35241 Composer vulnerable to command injection via malicious git branch name — composer CWE-77 8.8 High 2024-06-10
CVE-2024-24821 Code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in Composer — composer CWE-829 8.8 High 2024-02-08
CVE-2023-43655 Remote Code Execution via web-accessible composer.phar — composer CWE-74 6.4 Medium 2023-09-29
CVE-2022-24828 Missing input validation can lead to command execution in composer — composer CWE-20 8.3 High 2022-04-13
CVE-2021-41116 Command injection in composer on Windows — composer CWE-77 8.2 High 2021-10-05
CVE-2021-29472 Missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composer — composer CWE-88 8.8 High 2021-04-27

This page lists every published CVE security advisory associated with composer. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.