🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. Both vulnerabilities are located in Composer's Perforce VCS driver and involve insufficient escaping of values used in shell command construction. They can be exploited on any system even if you don't have Perforce installed. No exploitation detected on Packagist-org and Private Packagist. #php #phpc #composerphp
The Imagine project is looking for partners to promote The Second World Digital Strike on Feb 24 2027
Full details on our blog: https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/