An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS03YzZwLTg0OGotd2g1aM4AA5KP

Composer code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php


Several files within the local working directory are included during the invocation of Composer and in the context of the executing user.

As such, under certain conditions arbitrary code execution may lead to local privilege escalation, provide lateral user movement or malicious code execution when Composer is invoked within a directory with tampered files.

All Composer CLI commands are affected, including composer.phar's self-update.

The following are of high risk:


2.7.0, 2.2.23


Where not possible, the following should be addressed:

A reset can also be done on these files by the following:

rm vendor/composer/installed.php vendor/composer/InstalledVersions.php
composer install --no-scripts --no-plugins
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 22 days ago
Updated: 21 days ago

CVSS Score: 8.8
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Identifiers: GHSA-7c6p-848j-wh5h, CVE-2024-24821

Affected Packages

Versions: >= 2.3.0-rc1, < 2.7.0, >= 2.0.0-alpha1, < 2.2.23
Fixed in: 2.7.0, 2.2.23