PHP Composerã®èå¼±æ§CVE-2026-40261ï¼CVSS 8.8ï¼ã¯Perforceæªã¤ã³ã¹ãã¼ã«ã§ãä»»æã³ã¼ãå®è¡ãæç«ãcomposer install/requireã§RCEãªã¹ã¯ãä¿®æ£ç2.9.6/2.2.27ã¸ä»ããcomposer self-updateã§æ´æ°ãå ¨PHPéçºè ã»CIç°å¢ãå½±é¿å¯¾è±¡ã ð¨ CVE-2026-40261 / CVE-2026-40176 â Composer Perforce Command Injection CVSS: 8.8 Highï¼CVE-2026-40261, AV:Nï¼ï¼7.8 Highï¼CVE-2026-40176, AV:Lï¼ å½±é¿: Composer 2.0ã2.2.26ï¼LTSï¼ã»2.3ã2.9.5ï¼mainlineï¼ ä¿®æ£ç: 2.2.27ï¼LTSï¼ã»2.9.6以éï¼mainlineã2.9.7ã§regress


{{#tags}}- {{label}}
{{/tags}}