Getcomposer

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 17
    Known Exploited: 0
    0
    Critical Level Threats
    12
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-84361

    Composer: Perforce source URL permits P4PORT `rsh:` command execution

    Last Modified: Sep 03, 2026
    Published: Sep 01, 2026

    CVE-2026-45793

    Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs

    Last Modified: Jul 30, 2026
    Published: Jul 15, 2026

    CVE-2026-59947

    Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

    Last Modified: Jul 10, 2026
    Published: Jul 08, 2026

    CVE-2026-59948

    Composer: Arbitrary file write outside vendor via malicious transitive package name

    Last Modified: Jul 10, 2026
    Published: Jul 08, 2026

    CVE-2026-59946

    Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

    Last Modified: Jul 10, 2026
    Published: Jul 08, 2026
    Items Per Page
    Getcomposer Vulnerabilities & Security CVEs | CVE-DB