Vulnerabilities
Critical PHP Composer Flaws Allow Remote Command Execution via Perforce Driver
Two high-severity command injection vulnerabilities (CVE-2026-40176, CVE-2026-40177) in PHP Composer's Perforce driver enable arbitrary command execution on developer systems during package operations.
CVE-2026-40176CVE-2026-40177
3 min read