Found 1 security vulnerability advisory affecting 1 package: Package: composer/composer Severity: high Advisory ID: PKSA-ym19-cy3j-z6df CVE: CVE-2026-84361 Title: Composer arbitrary command execution via a malicious package's Perforce source URL URL: https://github.com/advisories/GHSA-rvx4-ffvw-m9q3 Affected versions: >=1.0,<2.2.30|>=2.3.0,<2.10.3 Reported at: 2026-09-08T21:25:41+00:00