/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-35241

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-35241

Severity

8.8

High

CVSS V3

Summary

Composer vulnerable to command injection via malicious git branch name

Description

Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the status, reinstall and remove commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using --prefer-dist or the preferred-install: dist config setting.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing