CVE-2026-84361
Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\Util\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.
Not on KEV
Not in CISA's Known Exploited Vulnerabilities catalogue as of the last daily pull. Absence is not proof of safety.
0%
Chance of exploitation in the next 30 days, 35th percentile of all CVEs. A forecast; KEV outranks it.
—
no vector published
—
No exposure census on this CVE's dispatches.
- nvd.nist.gov ↗
- first.org · EPSS ↗
- github.com/composer/composer/commit/0aac50528e83ed635cf788333635897469440220 ↗
- github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af ↗
- github.com/composer/composer/releases/tag/2.10.3 ↗
- github.com/composer/composer/releases/tag/2.2.30 ↗
- github.com/composer/composer/security/advisories/GHSA-rvx4-ffvw-m9q3 ↗
Watch this one?
Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.