DEBIAN-CVE-2026-84361

Source
https://security-tracker.debian.org/tracker/CVE-2026-84361
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84361.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-84361
Upstream
Published
2026-09-01T21:18:47Z
Modified
2026-09-10T08:47:32Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\Util\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.

References

Affected packages

Debian:12 / composer

Package

Name
composer
Purl
pkg:deb/debian/composer?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.5.5-1
2.5.5-1+deb12u1
2.5.5-1+deb12u2
2.5.5-1+deb12u3
2.5.5-1+deb12u4
2.5.5-1+deb12u5
2.5.6-1
2.5.7-1
2.5.8-1
2.6.2-1
2.6.3-1
2.6.4-1
2.6.5-1
2.6.6-1
2.7.1-1
2.7.1-2
2.7.2-1
2.7.4-1
2.7.6-1
2.7.6-2
2.7.6-3
2.7.7-1
2.7.7-2
2.7.8-1
2.7.9-1
2.8.0-1
2.8.1-1
2.8.2-1
2.8.3-1
2.8.4-1
2.8.4-2
2.8.4-3
2.8.5-1
2.8.6-1
2.8.8-1
2.8.9-1
2.8.10-1
2.8.11-1
2.8.11-2
2.8.12-1
2.9.0~rc1-1
2.9.1-1
2.9.2-1
2.9.3-1
2.9.4-1
2.9.5-1
2.9.7-1
2.9.8-1
2.10.0~rc1-1
2.10.0~rc1-2
2.10.0~rc1-3
2.10.0~rc2-1
2.10.0-1
2.10.1-1
2.10.1-2
2.10.2-1
2.10.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84361.json"

Debian:13 / composer

Package

Name
composer
Purl
pkg:deb/debian/composer?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.8.8-1
2.8.8-1+deb13u1
2.8.8-1+deb13u2
2.8.8-1+deb13u3
2.8.9-1
2.8.10-1
2.8.11-1
2.8.11-2
2.8.12-1
2.9.0~rc1-1
2.9.1-1
2.9.2-1
2.9.3-1
2.9.4-1
2.9.5-1
2.9.7-1
2.9.8-1
2.10.0~rc1-1
2.10.0~rc1-2
2.10.0~rc1-3
2.10.0~rc2-1
2.10.0-1
2.10.1-1
2.10.1-2
2.10.2-1
2.10.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84361.json"

Debian:14 / composer

Package

Name
composer
Purl
pkg:deb/debian/composer?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.10.3-1

Affected versions

2.*
2.8.8-1
2.8.9-1
2.8.10-1
2.8.11-1
2.8.11-2
2.8.12-1
2.9.0~rc1-1
2.9.1-1
2.9.2-1
2.9.3-1
2.9.4-1
2.9.5-1
2.9.7-1
2.9.8-1
2.10.0~rc1-1
2.10.0~rc1-2
2.10.0~rc1-3
2.10.0~rc2-1
2.10.0-1
2.10.1-1
2.10.1-2
2.10.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84361.json"