Skip to content

Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial

High severity GitHub Reviewed Published Apr 27, 2021 in composer/composer • Updated Jan 24, 2024

No closed alerts for this advisory

Give feedback on Dependabot alerts