Two high-severity vulnerabilities in PHP Composer allow attackers to execute arbitrary commands through malicious composer.json files or source references. These flaws impact the Perforce VCS driver and can be exploited by injecting shell metacharacters, posing a significant risk to developers using PHP projects with Perforce. Developers should update to Composer version 2.9.6 or 2.2.27 immediately to mitigate these risks.
Read the full article at Security Affairs
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



