CVE-2026-84361 | Composer up to 2.2.29/2.10.2 Perforce ComposerUtilPerforce source.url os command injection

SecurityVulns

A vulnerability classified as problematic has been found in Composer up to 2.2.29/2.10.2. This issue affects the function ComposerUtilPerforce of the component Perforce. The manipulation of the argument source.url leads to os command injection.

This vulnerability is uniquely identified as CVE-2026-84361. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More