Skip to content

fix: Fixing security vulns found in composer - #40

Merged
cigamit merged 1 commit into
mainfrom
ascender-cves
May 15, 2026
Merged

fix: Fixing security vulns found in composer#40
cigamit merged 1 commit into
mainfrom
ascender-cves

Conversation

@TheWitness

Copy link
Copy Markdown
Collaborator
+-------------------+----------------------------------------------------------------------------------+
| Package           | composer/composer                                                                |
| Severity          |                                                                                  |
| Advisory ID       | PKSA-pwvr-3754-v57r                                                              |
| CVE               | CVE-2026-45793                                                                   |
| Title             | Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs             |
| URL               | https://github.com/composer/composer/security/advisories/GHSA-f9f8-rm49-7jv2     |
| Affected versions | >=2.3,<2.9.8|>=2.0.0,<2.2.28|>=1.0,<1.10.28                                      |
| Reported at       | 2026-05-13T07:00:00+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | composer/composer                                                                |
| Severity          | high                                                                             |
| Advisory ID       | PKSA-t5r2-p5q9-mtpn                                                              |
| CVE               | CVE-2026-40261                                                                   |
| Title             | Command injection via malicious Perforce source reference/url                    |
| URL               | https://github.com/composer/composer/security/advisories/GHSA-gqw4-4w2p-838q     |
| Affected versions | >=2.3,<2.9.6|>=1.0,<2.2.27                                                       |
| Reported at       | 2026-04-14T09:42:00+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | composer/composer                                                                |
| Severity          | high                                                                             |
| Advisory ID       | PKSA-6bp1-9hfj-2cgv                                                              |
| CVE               | CVE-2026-40176                                                                   |
| Title             | Command injection via malicious Perforce repository definition                   |
| URL               | https://github.com/composer/composer/security/advisories/GHSA-wg36-wvj6-r67p     |
| Affected versions | >=2.3,<2.9.6|>=1.0,<2.2.27                                                       |
| Reported at       | 2026-04-14T09:42:00+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | composer/composer                                                                |
| Severity          | low                                                                              |
| Advisory ID       | PKSA-1gck-s111-yq7g                                                              |
| CVE               | CVE-2025-67746                                                                   |
| Title             | Composer is vulnerable to ANSI sequence injection                                |
| URL               | https://github.com/advisories/GHSA-59pp-r3rg-353g                                |
| Affected versions | >=2.3.0,<2.9.3|>=2.0.0,<2.2.26                                                   |
| Reported at       | 2025-12-30T17:44:10+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | symfony/process                                                                  |
| Severity          | medium                                                                           |
| Advisory ID       | PKSA-rkkf-636k-qjb3                                                              |
| CVE               | CVE-2026-24739                                                                   |
| Title             | Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to           |
|                   | destructive file operations on Windows                                           |
| URL               | https://github.com/advisories/GHSA-r39x-jcww-82v6                                |
| Affected versions | >=8.0,<8.0.5|>=7.4,<7.4.5|>=7.3,<7.3.11|>=6.4,<6.4.33|<5.4.51                    |
| Reported at       | 2026-01-28T21:28:10+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+

@ciq-it-service-account

ciq-it-service-account commented May 15, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@cigamit
cigamit merged commit 0e558b9 into main May 15, 2026
3 of 4 checks passed
@cigamit
cigamit deleted the ascender-cves branch May 15, 2026 15:59
@TheWitness
TheWitness removed the request for review from Copilot May 15, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

3 participants