{"id":"SUSE-SU-2026:1784-1","summary":"Security update for php-composer2","details":"This update for php-composer2 fixes the following issues:\n\n- CVE-2026-40176: arbitrary command injection via malicious Perforce repository definition (bsc#1262254).\n- CVE-2026-40261: arbitrary command injection via malicious Perforce source reference/url (bsc#1262255).\n","modified":"2026-05-12T18:24:26.613452776Z","published":"2026-05-08T17:05:56Z","related":["CVE-2026-40176","CVE-2026-40261"],"upstream":["CVE-2026-40176","CVE-2026-40261"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261784-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262255"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40176"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40261"}],"schema_version":"1.7.5"}