Skip to main content
Vulnerability Database/CVE-2025-67746

CVE-2025-67746: Getcomposer Composer DOS Vulnerability

CVE-2025-67746 is a denial of service vulnerability in Getcomposer Composer that allows attackers to inject ANSI control characters causing terminal output issues. This article covers the technical details, affected versions, security impact, and how to protect your systems.

Published:

CVE-2025-67746 Overview

CVE-2025-67746 affects Composer, the widely used dependency manager for PHP. The vulnerability allows attackers who control remote sources that Composer downloads from to inject ANSI control characters into terminal output. When Composer commands render this attacker-controlled data, the terminal may display mangled output, cause user confusion, or result in denial of service of the terminal application. The flaw is classified under CWE-74 (Improper Neutralization of Special Elements in Output). Composer versions on the 2.x branch prior to 2.2.26 and 2.9.3 are affected. Patched releases 2.2.26 and 2.9.3 sanitize the output.

Critical Impact

Attacker-controlled remote package metadata can inject ANSI escape sequences into Composer terminal output, potentially causing display mangling or terminal denial of service.

Affected Products

  • Composer 2.x branch prior to 2.2.26
  • Composer 2.x branch prior to 2.9.3
  • All PHP projects consuming remote package sources through vulnerable Composer versions

Discovery Timeline

  • 2025-12-30 - CVE-2025-67746 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-67746

Vulnerability Analysis

Composer fetches package metadata, author names, descriptions, and audit advisories from remote sources such as Packagist or third-party repositories. Several Composer commands render this data directly to the terminal without neutralizing embedded control sequences. An attacker who publishes a malicious package or controls a repository can embed ANSI escape codes in fields that Composer prints. When a user runs commands like composer audit, composer show, or composer require, the terminal interprets these sequences. Consequences include hiding text, overwriting displayed content, changing cursor position, or issuing terminal control commands that hang or crash the emulator. No proven code execution exploit exists, which is why the vulnerability carries a low severity rating.

Root Cause

The root cause is missing output sanitization in the console I/O layer and in the auditor output paths. Data returned from remote sources was passed to the Symfony Console renderer without stripping or escaping ANSI control characters. The patch introduces a ConsoleIO::sanitize() helper and applies it to rendered rows in src/Composer/Advisory/Auditor.php and elsewhere.

Attack Vector

Exploitation requires that a victim run a Composer command that pulls or displays attacker-controlled metadata from a remote source. Attackers must control a package or repository the victim consumes. The attack is passive from the victim's perspective and requires no local privilege, but it depends on user interaction with the affected command.

php
// Patch: src/Composer/Advisory/Auditor.php
$io->getTable()
    ->setHorizontal()
    ->setHeaders($headers)
-   ->addRow($row)
+   ->addRow(ConsoleIO::sanitize($row))
    ->setColumnWidth(1, 80)
    ->setColumnMaxWidth(1, 80)
    ->render();

Source: composer/composer commit 5db1876a

php
// Patch: src/Composer/IO/ConsoleIO.php
namespace Composer\IO;

+use Composer\Pcre\Preg;
use Composer\Question\StrictConfirmationQuestion;
use Symfony\Component\Console\Helper\HelperSet;
use Symfony\Component\Console\Helper\ProgressBar;

Source: composer/composer commit 1d40a95c

Detection Methods for CVE-2025-67746

Indicators of Compromise

  • Unexpected ANSI escape sequences (bytes 0x1B[) appearing in captured Composer command output or CI/CD build logs.
  • Terminal sessions that hang, freeze, or display corrupted characters immediately after running composer audit, composer show, or composer require.
  • Package metadata fields (name, description, author) containing non-printable control characters when inspected in composer.lock or repository JSON.

Detection Strategies

  • Scan CI/CD build artifacts and Composer log output for ESC (\\x1B) and CSI (\\x9B) byte sequences that should not appear in dependency metadata.
  • Inventory Composer versions across development workstations and build agents; flag any host running a 2.x version older than 2.2.26 or 2.9.3.
  • Monitor for use of untrusted or newly added Composer repositories in composer.jsonrepositories blocks.

Monitoring Recommendations

  • Ingest CI/CD pipeline logs into a centralized log platform and alert on control-character patterns in Composer output.
  • Track outbound network connections from build agents to unexpected Composer or Packagist mirrors.
  • Audit changes to composer.json and composer.lock for new package sources introduced by unauthorized contributors.

How to Mitigate CVE-2025-67746

Immediate Actions Required

  • Upgrade Composer to version 2.2.26 (for the 2.2 LTS line) or 2.9.3 (for the current 2.x line) on all developer workstations, build servers, and container images.
  • Rebuild container base images that bundle Composer and redistribute updated images to CI/CD pipelines.
  • Restrict composer.jsonrepositories entries to trusted sources and review recent additions.

Patch Information

The Composer maintainers released fixes in Composer v2.2.26 and Composer v2.9.3. The fix introduces a sanitization routine in ConsoleIO and applies it to output paths that render remote metadata, including the Auditor table renderer. Details are documented in the GitHub Security Advisory GHSA-59pp-r3rg-353g.

Workarounds

  • Run Composer commands with output redirected to a file rather than an interactive terminal until patched versions are deployed.
  • Limit package sources to vetted internal mirrors or private Packagist instances that validate package metadata.
  • Avoid running composer audit or composer show against untrusted repositories on production or shared terminals.
bash
# Upgrade Composer to a patched release
composer self-update 2.9.3

# Or for the 2.2 LTS branch
composer self-update 2.2.26

# Verify installed version
composer --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.