Command injection through Composer via Perforce package information

PPSA-202604-1


Summary

A command injection vulnerability in Composer, which Private Packagist uses to read and process packages, allowed package maintainers and malicious or compromised Composer repositories to run shell commands on the servers that process package updates. Composer did not escape the source reference and source URL of packages with a Perforce source before using them in shell commands.

Who was affected

Private Packagist Cloud until April 10, 2026, when we disabled Perforce support as a precaution, and Private Packagist Self-Hosted installations running a version before 2.0.32. On Self-Hosted, the affected component is the background worker that processes package updates.

Impact

An attacker able to provide package information to Private Packagist, as a malicious package maintainer or through a malicious or compromised Composer repository, could have run arbitrary shell commands on the servers that process package updates. The servers that process package updates have access to the code of the packages they process and to the credentials Private Packagist uses to fetch them. An attacker could therefore have accessed the code and credentials of the packages processed on these servers.

What we did

On April 10, 2026, before the vulnerability was published, we disabled Perforce support in Private Packagist Cloud as a precaution. On April 14, 2026, we updated Composer in Private Packagist Cloud and released Private Packagist Self-Hosted 2.0.32. Private Packagist also no longer delivers Perforce source information to Composer, to help protect customers who still use older Composer versions.

To the best of our knowledge, this vulnerability was not exploited on Private Packagist Cloud. Before the vulnerability was published, we scanned the stored package information of all organizations on Private Packagist Cloud for package versions with a Perforce source, and checked their source references and source URLs for injected shell commands. We found no package information attempting to exploit this vulnerability.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.32 or any later version. We recommend upgrading to the latest release. Afterwards, run this command to verify that none of the package information on your installation attempts to exploit this vulnerability. It lists every package version with suspicious Perforce source information, and reports "No compromising versions found" otherwise. If it lists any package versions, contact us at contact@packagist.com.
    kubectl exec $(kubectl get pods --field-selector=status.phase=Running --no-headers -o custom-columns=":metadata.name"|grep worker-) -- /bin/sh -c "/srv/manager/bin/console packagist:audit --vulnerability CVE-2026-40261"
    
  • Private Packagist Cloud: No action is required.
  • We recommend that everyone keeps the Composer version they use up to date, as described in the Composer advisory.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!