VendorsGetcomposercomposerall versions
Vulnerabilities

Getcomposer Composer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-41116
Command injection in composer on Windows
Published 2021-10-05 · Modified
9.8EPSS 0.029
CVE-2021-29472
Missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composer
Published 2021-04-27 · Modified
8.8EPSS 0.046
CVE-2026-40261
Composer has Command Injection via Malicious Perforce Reference
Published 2026-04-15 · Modified
8.8EPSS 0.019
CVE-2022-24828
Missing input validation can lead to command execution in composer
Published 2022-04-13 · Modified
8.8EPSS 0.019
CVE-2023-43655
Remote Code Execution via web-accessible composer.phar
Published 2023-09-29 · Analyzed
8.8EPSS 0.014
CVE-2015-8371
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because of the way that dist packages are cached. The cache key is derived from the package name, the dist type, and certain other data from the package repository (which may simply be a commit hash, and thus can be found by an attacker). Versions through 1.0.0-alpha11 are affected, and 1.0.0 is unaffected.
Published 2023-09-21 · Modified
8.8EPSS 0.007
CVE-2024-24821
Code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in Composer
Published 2024-02-08 · Modified
8.8EPSS 0.003
CVE-2026-40176
Composer is vulnerable to Command Injection via Malicious Perforce Repository
Published 2026-04-15 · Modified
7.8EPSS 0.010
CVE-2025-67746
Composer vulnerable to ANSI sequence injection
Published 2025-12-30 · Analyzed
4.3EPSS 0.005