High [CVE-2026-84361] Arbitrary code execution via malicious Perforce source URL
This high-severity Red Hat Linux advisory covers CVE-2026-84361 affecting Red Hat Hardened Images.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in Composer. A malicious dependency package from a custom Composer repository or an untrusted `composer.lock` file could exploit a vulnerability in how Composer handles Perforce source URLs.
By setting `source.type` to `perforce` and `source.url` to an `rsh:` or `jsh:` P4PORT value, an attacker could cause the Perforce `p4` client to execute arbitrary local commands. This could lead to arbitrary code execution with the privileges of the user or continuous integration (CI) account running Composer.
Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78.
Affected Red Hat products: Red Hat Hardened Images. Red Hat does not currently list a fixing RHSA for this CVE.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
- 2.10.3
- 2.2.30
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- To mitigate this issue, avoid installing the Perforce `p4` client on systems where Composer is used, unless explicitly required. Additionally, ensure that Composer only processes dependencies from trusted repositories and `composer.lock` files to prevent the introduction of malicious `source.url` values.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.