Web Hack List

Collected research

PHP Supply Chain Attack on Composer

Sonar traced user-controlled repository URLs through Composer's VCS drivers into shell commands, where escaping prevented shell metacharacters but not leading-option argument injection. A malicious Packagist package URL used Mercurial's --config option to redefine hg identify as a shell alias, yielding command execution on Packagist and a high-impact package-registry supply-chain risk.

Record

Researcher
Thomas Chauchefoin
Published by
Sonar
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Thomas Chauchefoin, first published at the original source. Preserved copies are kept so the citation survives its host.