Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on packagist.org for example where the composer.json's `readme` field can be used as a vector for injecting parameters into hg/Mercurial via the `$file` argument, or git via the `$identifier` argument if you allow arbitrary data there (Packagist does not, but maybe other integrators do). Composer itself should not be affected by the vulnerability as it does not call `getFileContent` with arbitrary data into `$file`/`$identifier`. To the best of our knowledge this was not abused, and the vulnerability has been patched on packagist.org and Private Packagist within a day of the vulnerability report.
CVSS Details
- CVSS 3.1 Base Score: 8.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-composer | Aug 22, 2024 | Apr 13, 2022 | |
| Debian | debian-upgrade-composer | Jul 30, 2024 | Apr 13, 2022 | |
| Freebsd | freebsd-upgrade-package-php74-composerfreebsd-upgrade-package-php80-composerfreebsd-upgrade-package-php81-composerfreebsd-upgrade-package-php74-composer2freebsd-upgrade-package-php80-composer2freebsd-upgrade-package-php81-composer2 | Nov 4, 2022 | Apr 13, 2022 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-php-composer | Aug 7, 2025 | Aug 6, 2025 | |
| Suse | — | suse-upgrade-php-composersuse-upgrade-php-composer2 | Oct 26, 2022 | Apr 13, 2022 |
| Ubuntu | ubuntu-pro-upgrade-composer | Jun 26, 2025 | Apr 13, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub