← Vulnerability feed

Vulnerability record · CVE-2021-41116 · published 5 October 2021

CVE-2021-41116: Getcomposer composer command injection vulnerability

Getcomposer · Composer

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

9.8 CVSS 3.1 Critical EPSS 2.9% · top 13.6% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 7.5
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41116 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed9.8CVE-2021-44790Apache HTTP Server mod_lua multipart parser buffer overflowA crafted request body triggers an out-of-bounds write in the mod_lua multipart parser when r:parsebody() is called from Lua scripts. The flaw affect…EPSS 97%analysed9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2020-11656Sqlite use after free vulnerabilityIn SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELEC…EPSS 7.6%9.8CVE-2019-19919Handlebars.js project handlebars.js prototype pollution vulnerabilityVersions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto…EPSS 7.1%9.8CVE-2019-19646Sqlite vulnerabilitypragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.EPSS 5.4%9.1CVE-2020-7061Php out-of-bounds read vulnerabilityIn PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR fi…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2021-41116), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.