Security advisories


To report a vulnerability, see our bug bounty program.

Private network filter could be bypassed with IPv6 addresses 2026-06-04
PPSA-202606-1 Cloud
Previous Composer authentication token stayed valid after regenerating it 2026-05-26
PPSA-202605-2 Cloud Self-Hosted < 2.0.33
API request signatures did not cover query parameters 2026-05-08
PPSA-202605-1 Cloud Self-Hosted < 2.0.33
Command injection through Composer via Perforce package information 2026-04-14
PPSA-202604-1 Cloud Self-Hosted < 2.0.32 Upstream CVE-2026-40261
Team invitations could be used to join a different team 2024-10-03
PPSA-202410-1 Cloud Self-Hosted < 2.0.5
Reflected cross-site scripting in the custom package form 2024-06-12
PPSA-202406-4 Cloud Self-Hosted < 2.0.3
Reflected cross-site scripting in the integration form 2024-06-12
PPSA-202406-3 Cloud Self-Hosted < 2.0.3
Open redirect in the link to join a team 2024-06-12
PPSA-202406-2 Cloud Self-Hosted < 2.0.3
Mirrored repository and notification URLs could redirect to insecure URLs 2024-06-12
PPSA-202406-1 Cloud Self-Hosted < 2.0.3
Packages of another organization could be imported 2024-05-29
PPSA-202405-1 Cloud Self-Hosted < 2.0.3
Billing team members could add packages from mirrored repositories 2024-04-08
PPSA-202404-2 Cloud Self-Hosted < 2.0.3
Organization log accessible to all organization members 2024-04-05
PPSA-202404-1 Cloud Self-Hosted < 2.0.3
Missing CSRF protection on several actions 2024-03-21
PPSA-202403-2 Cloud Self-Hosted < 2.0.2
Owners team memberships could be managed through the API 2024-03-12
PPSA-202403-1 Cloud Self-Hosted < 2.0.2
Missing CSRF protection when disconnecting OAuth accounts 2024-02-27
PPSA-202402-1 Cloud Self-Hosted < 2.0.2
Password reset links did not expire 2024-01-03
PPSA-202401-1 Cloud Self-Hosted < 2.0.1
Multi-factor authentication not required after OAuth login 2023-09-01
PPSA-202309-1 Cloud Self-Hosted = 1.12.0 | = 1.12.0-pl1 | = 1.12.0-pl2
Argument injection through Composer when processing packages 2022-04-13
PPSA-202204-1 Cloud Self-Hosted < 1.11.3 Upstream CVE-2022-24828
Command injection through Composer when processing packages 2021-04-27
PPSA-202104-1 Cloud Self-Hosted < 1.10.6 Upstream CVE-2021-29472
Sensitive data exposed through a Replicated API 2020-03-23
PPSA-202003-1 Self-Hosted < 1.9.9 Upstream CVE-2020-10590

Start Free Trial

Login to create an organization and start your free trial!