logo

Database

Server side template injection In composer/composer

Description

Improper escaping of command arguments on Windows leading to command injection

Impact

Windows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected.

Patches

1.10.23 and 2.1.9 fix the issue

Workarounds

None

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions