{"id":"UBUNTU-CVE-2025-67746","details":"Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangled output and potentially leading to confusion or DoS of the terminal application. There is no proven exploit and this has thus a low severity but we still publish a CVE as it has potential for abuse, and we want to be on the safe side informing users that they should upgrade. Versions 2.2.26 and 2.9.3 contain a patch for the issue.","modified":"2026-05-20T16:11:28.705236750Z","published":"2025-12-30T16:15:00Z","upstream":["CVE-2025-67746"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-67746"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-67746"},{"type":"REPORT","url":"https://github.com/composer/composer/security/advisories/GHSA-59pp-r3rg-353g"},{"type":"REPORT","url":"https://github.com/composer/composer/commit/1d40a95c9d39a6b7f80d404ab30336c586da9917"},{"type":"REPORT","url":"https://github.com/composer/composer/commit/5db1876a76fdef76d3c4f8a27995c434c7a43e71"},{"type":"REPORT","url":"https://github.com/composer/composer/releases/tag/2.2.26"},{"type":"REPORT","url":"https://github.com/composer/composer/releases/tag/2.9.3"}],"affected":[{"package":{"name":"composer","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/composer?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.0~alpha10+20150602-1","1.0.0~alpha10+20150602-2","1.0.0~alpha11-1","1.0.0~alpha11-1ubuntu1","1.0.0~alpha11-2","1.0.0~alpha11-3","1.0.0~beta1-1ubuntu1","1.0.0~beta2-1","1.0.0~beta2-1ubuntu0.1~esm1","1.0.0~beta2-1ubuntu0.1~esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"composer","binary_version":"1.0.0~beta2-1ubuntu0.1~esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67746.json"}},{"package":{"name":"composer","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/composer?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.1-1","1.5.2-1","1.6.2-1","1.6.3-1","1.6.3-1ubuntu0.1~esm1","1.6.3-1ubuntu0.1~esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"composer","binary_version":"1.6.3-1ubuntu0.1~esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67746.json"}},{"package":{"name":"composer","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/composer?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.0-2","1.9.1-1","1.9.2-1","1.9.3-1","1.10.0-1","1.10.1-1","1.10.1-1ubuntu0.1~esm1","1.10.1-1ubuntu0.1~esm2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.10.1-1ubuntu0.1~esm2","binary_name":"composer"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67746.json"}},{"package":{"name":"composer","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/composer?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.9-2ubuntu2","2.0.9-2ubuntu3","2.0.13-1ubuntu1","2.1.12-1ubuntu1","2.2.6-2ubuntu4","2.2.6-2ubuntu4+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.2.6-2ubuntu4+esm1","binary_name":"composer"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67746.json"}},{"package":{"name":"composer","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/composer?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.5.8-1","2.6.5-1","2.6.6-1","2.7.1-2","2.7.1-2ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"composer","binary_version":"2.7.1-2ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67746.json"}},{"package":{"name":"composer","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/composer?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8.6-1","2.8.8-1"],"ecosystem_specific":{"binaries":[{"binary_name":"composer","binary_version":"2.8.8-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67746.json"}},{"package":{"name":"composer","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/composer?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8.8-1","2.9.5-1"],"ecosystem_specific":{"binaries":[{"binary_name":"composer","binary_version":"2.9.5-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67746.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]}