THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rvx4-ffvw-m9q3 (high) — Composer arbitrary command execution via a malicious package's Perforce source URL

[GHSA] GHSA-rvx4-ffvw-m9q3 (high) — Composer arbitrary command execution via a malicious package's Perforce source URL

highgithub_advisoriesPublished 2026-09-08

GHSA-rvx4-ffvw-m9q3 Severity: high CVE: CVE-2026-84361

Composer arbitrary command execution via a malicious package's Perforce source URL

## Summary

If the `p4` Perforce CLI client is installed, a malicious dependency package from a package repository allowing arbitrary perforce source URLs (packagist.org is safe) could execute arbitrary commands when running `composer install` or `composer upd

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rvx4-ffvw-m9q3