Related Vulnerabilities: CVE-2021-41116  

Windows users running Composer before version 2.1.9 to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected.

Severity Medium

Remote Yes

Type Arbitrary command execution

Description

Windows users running Composer before version 2.1.9 to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected.

AVG-2446 composer 2.1.8-1 2.1.9-1 Medium Not affected

https://github.com/composer/composer/security/advisories/GHSA-frqg-7g38-6gcf
https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa