{"id":"openSUSE-SU-2026:20670-1","summary":"Security update for php-composer2","details":"This update for php-composer2 fixes the following issues:\n\n- CVE-2025-67746: ANSI control characters injection in terminal output of various Composer commands via attacker\n  controlled remote sources (bsc#1255768).\n- CVE-2026-40176: arbitrary command injection via malicious Perforce repository definition (bsc#1262254).\n- CVE-2026-40261: arbitrary command injection via malicious Perforce source reference/url (bsc#1262255).\n","modified":"2026-05-07T18:24:02.286030Z","published":"2026-05-04T10:46:30Z","related":["CVE-2025-67746","CVE-2026-40176","CVE-2026-40261"],"upstream":["CVE-2025-67746","CVE-2026-40176","CVE-2026-40261"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255768"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262255"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-67746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40176"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40261"}],"schema_version":"1.7.5"}