getcomposer records
12 published records for vendor getcomposer.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 91.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-276 Incorrect Default Permissions1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-41116No exploit | Command injection in composer on Windowsgetcomposer · composer · CWE-77 | Critical9.8 | — | 2.9% | Oct 5, 2021 |
36Monitor | CVE-2021-29472No exploit | Missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composergetcomposer · composer · CWE-88 | High8.8 | — | 4.6% | Apr 27, 2021 |
36Monitor | CVE-2024-35242Proof of concept | Composer vulnerable to command injection via malicious git/hg branch namescomposer · composer · CWE-77 | High8.8 | — | 3.3% | Jun 10, 2024 |
36Monitor | CVE-2026-40261Proof of concept | Composer has Command Injection via Malicious Perforce Referencegetcomposer · composer · CWE-20 | High8.8 | — | 1.9% | Apr 15, 2026 |
36Monitor | CVE-2022-24828No exploit | Missing input validation can lead to command execution in composergetcomposer · composer · CWE-20 | High8.8 | — | 1.9% | Apr 13, 2022 |
35Monitor | CVE-2023-43655No exploit | Remote Code Execution via web-accessible composer.phargetcomposer · composer · CWE-74 | High8.8 | — | 1.4% | Sep 29, 2023 |
35Monitor | CVE-2024-35241No exploit | Composer vulnerable to command injection via malicious git branch namecomposer · composer · CWE-77 | High8.8 | — | 1.1% | Jun 10, 2024 |
35Monitor | CVE-2015-8371No exploit | Composer before 2016-02-10 allows cache poisoning from other projects built on the same host.getcomposer · composer · CWE-345 | High8.8 | — | 0.7% | Sep 21, 2023 |
32Monitor | CVE-2020-15145No exploit | Local privilege elevation in Composer-Setup for Windowsgetcomposer · composer-setup · CWE-276 | High8.2 | — | 0.4% | Aug 14, 2020 |
31Monitor | CVE-2026-40176Proof of concept | Composer is vulnerable to Command Injection via Malicious Perforce Repositorygetcomposer · composer · CWE-20 | High7.8 | — | 1.0% | Apr 15, 2026 |
31Monitor | CVE-2024-24821No exploit | Code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in Composergetcomposer · composer · CWE-829 | High7.8 | — | 0.3% | Feb 8, 2024 |
5Monitor | CVE-2025-67746No exploit | Composer vulnerable to ANSI sequence injectiongetcomposer · composer · CWE-74 | Low1.3 | — | 0.5% | Dec 30, 2025 |
- CVE-2021-4111640Plan
Command injection in composer on Windows
CriticalCVSS 9.8No exploitEPSS 3%getcomposer · composerOct 5, 2021
- CVE-2021-2947236Monitor
Missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composer
HighCVSS 8.8No exploitEPSS 5%getcomposer · composerApr 27, 2021
- CVE-2024-3524236Monitor
Composer vulnerable to command injection via malicious git/hg branch names
HighCVSS 8.8Proof of conceptEPSS 3%composer · composerJun 10, 2024
- CVE-2026-4026136Monitor
Composer has Command Injection via Malicious Perforce Reference
HighCVSS 8.8Proof of conceptEPSS 2%getcomposer · composerApr 15, 2026
- CVE-2022-2482836Monitor
Missing input validation can lead to command execution in composer
HighCVSS 8.8No exploitEPSS 2%getcomposer · composerApr 13, 2022
- CVE-2023-4365535Monitor
Remote Code Execution via web-accessible composer.phar
HighCVSS 8.8No exploitEPSS 1%getcomposer · composerSep 29, 2023
- CVE-2024-3524135Monitor
Composer vulnerable to command injection via malicious git branch name
HighCVSS 8.8No exploitEPSS 1%composer · composerJun 10, 2024
- CVE-2015-837135Monitor
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host.
HighCVSS 8.8No exploitEPSS 1%getcomposer · composerSep 21, 2023
- CVE-2020-1514532Monitor
Local privilege elevation in Composer-Setup for Windows
HighCVSS 8.2No exploitEPSS 0%getcomposer · composer-setupAug 14, 2020
- CVE-2026-4017631Monitor
Composer is vulnerable to Command Injection via Malicious Perforce Repository
HighCVSS 7.8Proof of conceptEPSS 1%getcomposer · composerApr 15, 2026
- CVE-2024-2482131Monitor
Code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in Composer
HighCVSS 7.8No exploitEPSS 0%getcomposer · composerFeb 8, 2024
- CVE-2025-677465Monitor
Composer vulnerable to ANSI sequence injection
LowCVSS 1.3No exploitEPSS 0%getcomposer · composerDec 30, 2025