CVE-2026-84361 is an OS command injection vulnerability in Composer's handling of Perforce package sources. A malicious package from a custom Composer repository, or an untrusted lockfile, can define a Perforce source URL using a dangerous Perforce transport. When Composer installs the package from source, its Perforce utility passes the attacker-controlled address to the installed Perforce client without validation. The Perforce client can then launch a local command under the privileges of the developer or CI account running Composer. Affected releases include Composer versions before 2.2.30 on the 2.2 branch and before 2.10.3 on the 2.x branch.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This nine-file repository is a functional, safety-oriented local proof of concept for CVE-2026-84361, an OS command injection in Composer's Perforce VCS driver. The core issue is that affected Composer versions pass package-controlled Perforce source.url metadata to the p4 client as P4PORT. Perforce p4 treats P4PORT values beginning with rsh: (and reportedly jsh:) as a local command transport, allowing a malicious package metadata entry or untrusted lock file to run a command under the Composer process account when source installation is selected. poc.php is the primary direct validator. It supports a non-executing dry run by default and requires --execute to invoke p4 -p with a generated rsh:touch payload. It checks for a randomized marker under the system temporary directory and removes it unless --keep-marker is supplied. composer.json contains the end-to-end malicious inline package definition, disabling Packagist and defining a perforce source URL of rsh:touch /tmp/cve-2026-84361-composer-marker. run-composer-poc.sh copies that configuration to a temporary workspace, runs composer update --prefer-source, and verifies whether the fixed marker was created. Dockerfile builds a PHP 8.3 CLI test image, downloads and SHA-256-verifies Perforce p4 release r25.2 for amd64 or arm64, and includes Composer 2.10.2, an affected version. compose.yaml constrains the runtime environment with no network, a read-only root filesystem, dropped capabilities, no-new-privileges, and writable tmpfs only at /tmp and /work. docker-entrypoint.sh defaults to executing the direct harmless PoC. The repository contains no reverse shell or external exfiltration behavior; its payload is limited to marker-file creation. Packagist-only workflows are described as unaffected because Packagist does not permit the requisite Perforce source metadata.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Composer command-execution vulnerability involving malicious Perforce source metadata. When Composer installs a dependency from source and the Perforce p4 client is present, an rsh: or jsh: P4PORT value can cause p4 to execute a local command as the user or CI account.
Unknown
A vulnerability identified as CVE-2026-84361 affecting the php-composer2 package on SUSE Linux 15. The provided CVSS vectors indicate high impact to confidentiality, integrity, and availability; the advisory reports that exploits are available.
A high-impact vulnerability referenced by the Fedora advisory. The provided CVSS vectors indicate confidentiality, integrity, and availability impact; the content does not provide a technical vulnerability description.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.