Skip to content
InYourGeek
visiteur@inyourgeek — shell
compléter historique ouvrirhelp
FR
← Back to the register

composer/composer

HighComposerCVE-2026-84361

What to do

Update composer/composer to 2.10.3 or later.

composer require composer/composer:^2.10.3

A remote code execution flaw affects the Composer package composer/composer. Affected versions: >= 2.3.0, < 2.10.3. Fixed from version 2.10.3.

What the flaw allows: An attacker can make the service run their own code.

Package
composer/composer
Ecosystem
Composer (PHP)
Class
Remote code execution
Affected versions
>= 2.3.0, < 2.10.3
Published on
September 8, 2026

Sources

Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.