THREAT OPS › Threat News › [GHSA] GHSA-rvx4-ffvw-m9q3 (high) — Composer arbitrary command execution via a malicious package's Perforce source URL
[GHSA] GHSA-rvx4-ffvw-m9q3 (high) — Composer arbitrary command execution via a malicious package's Perforce source URL
GHSA-rvx4-ffvw-m9q3 Severity: high CVE: CVE-2026-84361
Composer arbitrary command execution via a malicious package's Perforce source URL
## Summary
If the `p4` Perforce CLI client is installed, a malicious dependency package from a package repository allowing arbitrary perforce source URLs (packagist.org is safe) could execute arbitrary commands when running `composer install` or `composer upd
MITRE ATT&CK techniques
- Malicious PackageAML.T0011.001
Indicators of compromise
- CVE-2026-84361cve
- packagist.orgdomain
Original source: https://github.com/advisories/GHSA-rvx4-ffvw-m9q3