<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:31:29 +0000</lastBuildDate>
    <item>
      <title>BIT-composer-2021-41116 — Command injection in composer on Windows</title>
      <link>https://cve.radiocsirt.org/vuln/bit-composer-2021-41116</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-composer-2021-41116</guid>
    </item>
    <item>
      <title>certfr-2022-avi-370 — De multiples vulnérabilités ont été découvertes dans Tenable.sc.
Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-370</link>
      <description>certfr-2022-avi-370</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-370</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-SA12234 — Composer is an open source dependency manager for the PHP language</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-sa12234</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. Composer is an open source dependency manager for the PHP language.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. Composer is an open source dependency manager for the PHP language.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-sa12234</guid>
    </item>
    <item>
      <title>EUVD-2026-31496</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-31496</link>
      <description>EUVD-2026-31496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-31496</guid>
    </item>
    <item>
      <title>fkie_cve-2021-41116</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41116</link>
      <description>&lt;p&gt;Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-41116</guid>
    </item>
    <item>
      <title>GHSA-frqg-7g38-6gcf — Improper escaping of command arguments on Windows leading to command injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-frqg-7g38-6gcf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;### Impact
Windows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected.&lt;/p&gt;
&lt;p&gt;### Patches
1.10.23 and 2.1.9 fix the issue&lt;/p&gt;
&lt;p&gt;### Workarounds
None&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;### Impact
Windows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected.&lt;/p&gt;
&lt;p&gt;### Patches
1.10.23 and 2.1.9 fix the issue&lt;/p&gt;
&lt;p&gt;### Workarounds
None&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-frqg-7g38-6gcf</guid>
    </item>
    <item>
      <title>gsd-2021-41116</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-41116</link>
      <description>gsd-2021-41116</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-41116</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0132-1 — Security update for php-composer</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0132-1</link>
      <description>&lt;p&gt;Security update for php-composer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php-composer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0132-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-41116</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41116</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41116</guid>
    </item>
  </channel>
</rss>
