{"id":"GHSA-frqg-7g38-6gcf","summary":"Improper escaping of command arguments on Windows leading to command injection","details":"### Impact\nWindows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected. \n\n### Patches\n1.10.23 and 2.1.9 fix the issue\n\n### Workarounds\nNone\n","aliases":["BIT-composer-2021-41116","CVE-2021-41116"],"modified":"2026-07-08T06:29:33.018363297Z","published":"2021-10-05T20:23:18Z","database_specific":{"nvd_published_at":"2021-10-05T18:15:00Z","cwe_ids":["CWE-77"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-10-05T18:44:04Z"},"references":[{"type":"WEB","url":"https://github.com/composer/composer/security/advisories/GHSA-frqg-7g38-6gcf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41116"},{"type":"WEB","url":"https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/composer/composer/CVE-2021-41116.yaml"},{"type":"PACKAGE","url":"https://github.com/composer/composer"},{"type":"WEB","url":"https://www.sonarsource.com/blog/securing-developer-tools-package-managers"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2022-09"}],"affected":[{"package":{"name":"composer/composer","ecosystem":"Packagist","purl":"pkg:composer/composer/composer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.23"}]}],"versions":["1.0.0","1.0.0-alpha1","1.0.0-alpha10","1.0.0-alpha11","1.0.0-alpha2","1.0.0-alpha3","1.0.0-alpha4","1.0.0-alpha5","1.0.0-alpha6","1.0.0-alpha7","1.0.0-alpha8","1.0.0-alpha9","1.0.0-beta1","1.0.0-beta2","1.0.1","1.0.2","1.0.3","1.1.0","1.1.0-RC","1.1.1","1.1.2","1.1.3","1.10.0","1.10.0-RC","1.10.1","1.10.10","1.10.11","1.10.12","1.10.13","1.10.14","1.10.15","1.10.16","1.10.17","1.10.18","1.10.19","1.10.2","1.10.20","1.10.21","1.10.22","1.10.3","1.10.4","1.10.5","1.10.6","1.10.7","1.10.8","1.10.9","1.2.0","1.2.0-RC","1.2.1","1.2.2","1.2.3","1.2.4","1.3.0","1.3.0-RC","1.3.1","1.3.2","1.3.3","1.4.0","1.4.1","1.4.2","1.4.3","1.5.0","1.5.1","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.6.0","1.6.0-RC","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.7.0","1.7.0-RC","1.7.1","1.7.2","1.7.3","1.8.0","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.9.0","1.9.1","1.9.2","1.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-frqg-7g38-6gcf/GHSA-frqg-7g38-6gcf.json"}},{"package":{"name":"composer/composer","ecosystem":"Packagist","purl":"pkg:composer/composer/composer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0-alpha1"},{"fixed":"2.1.9"}]}],"versions":["2.0.0","2.0.0-RC1","2.0.0-RC2","2.0.0-alpha1","2.0.0-alpha2","2.0.0-alpha3","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-RC1","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-frqg-7g38-6gcf/GHSA-frqg-7g38-6gcf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"}]}