Vulnerability intelligence
CVE-2026-40261
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field without proper escaping. An attacker can inject arbitrary commands through crafted source reference or source url values containing shell metacharacters, even if Perforce is not installed.
CVSS Score
—
High
EPSS — Exploit Probability
1.7%
Riskier than 75% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
2 articles across 2 outlets · first covered Apr 14, 2026 · latest Apr 15, 2026
Coverage timeline
-
PHP Composer bugs enable RCE via Perforce VCS driversecurityaffairs.com · Apr 15, 2026
-
Composer Flaws Let Attackers Run Arbitrary Code via JSONthehackernews.com · Apr 14, 2026