{"id":"BIT-composer-2026-84361","summary":"Composer: Perforce source URL permits P4PORT `rsh:` command execution","details":"Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\\Util\\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.","aliases":["CVE-2026-84361","GHSA-rvx4-ffvw-m9q3"],"modified":"2026-09-10T09:30:07.136519043Z","published":"2026-09-07T05:38:23.093Z","database_specific":{"cpes":["cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:*","cpe:2.3:a:getcomposer:composer:*:*:*:*:*:php:*:*"],"severity":"High"},"references":[{"type":"WEB","url":"https://github.com/composer/composer/commit/0aac50528e83ed635cf788333635897469440220"},{"type":"WEB","url":"https://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af"},{"type":"WEB","url":"https://github.com/composer/composer/releases/tag/2.10.3"},{"type":"WEB","url":"https://github.com/composer/composer/releases/tag/2.2.30"},{"type":"WEB","url":"https://github.com/composer/composer/security/advisories/GHSA-rvx4-ffvw-m9q3"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84361"}],"affected":[{"package":{"name":"composer","ecosystem":"Bitnami","purl":"pkg:bitnami/composer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"2.2.30"},{"introduced":"2.3.0"},{"fixed":"2.10.3"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/composer/BIT-composer-2026-84361.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}],"schema_version":"1.9.0"}