{"source":"ghsa-composer","note":"Free 5-item preview. The full feed is $0.05/call at GET /v1/ghsa-composer/changes.","question":"Which new security vulnerabilities / CVEs affecting Composer/PHP packages were published since T, and how severe (CVSS) are they?","sample":[{"source":"ghsa-composer","entityId":"ghsa:GHSA-cvpc-hccg-wmw4","type":"advisory","title":"GHSA-cvpc-hccg-wmw4: Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration","summary":"MEDIUM severity. Affected: verbb/formie.","significance":6,"detectedAt":"2026-07-18T23:42:11.739Z","effectiveDate":"2026-07-17T19:05:57Z","sourceUrl":"https://github.com/advisories/GHSA-cvpc-hccg-wmw4","detail":{"severity":"medium","cve":null,"packages":"verbb/formie","cvss":6.3}},{"source":"ghsa-composer","entityId":"ghsa:GHSA-wg4w-wr5q-6vjc","type":"advisory","title":"GHSA-wg4w-wr5q-6vjc / CVE-2026-55578: Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection","summary":"HIGH severity. Affected: pheditor/pheditor.","significance":9,"detectedAt":"2026-07-16T20:35:02.992Z","effectiveDate":"2026-07-16T20:10:47Z","sourceUrl":"https://github.com/advisories/GHSA-wg4w-wr5q-6vjc","detail":{"severity":"high","cve":"CVE-2026-55578","packages":"pheditor/pheditor","cvss":8.8}},{"source":"ghsa-composer","entityId":"ghsa:GHSA-p4h7-p9rj-2pq2","type":"advisory","title":"GHSA-p4h7-p9rj-2pq2 / CVE-2026-55579: Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise","summary":"CRITICAL severity. Affected: pheditor/pheditor.","significance":10,"detectedAt":"2026-07-16T20:35:02.992Z","effectiveDate":"2026-07-16T20:11:23Z","sourceUrl":"https://github.com/advisories/GHSA-p4h7-p9rj-2pq2","detail":{"severity":"critical","cve":"CVE-2026-55579","packages":"pheditor/pheditor","cvss":9.8}},{"source":"ghsa-composer","entityId":"ghsa:GHSA-9643-6xjp-vx57","type":"advisory","title":"GHSA-9643-6xjp-vx57 / CVE-2026-54540: Pheditor has an authenticated terminal command whitelist bypass","summary":"HIGH severity. Affected: pheditor/pheditor.","significance":9,"detectedAt":"2026-07-16T20:07:24.441Z","effectiveDate":"2026-07-16T20:01:05Z","sourceUrl":"https://github.com/advisories/GHSA-9643-6xjp-vx57","detail":{"severity":"high","cve":"CVE-2026-54540","packages":"pheditor/pheditor","cvss":8.8}},{"source":"ghsa-composer","entityId":"ghsa:GHSA-xg43-5579-qw6v","type":"advisory","title":"GHSA-xg43-5579-qw6v: adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files","summary":"MEDIUM severity. Affected: adawolfa/isdoc, adawolfa/isdoc, adawolfa/isdoc, adawolfa/isdoc.","significance":7,"detectedAt":"2026-07-16T01:33:48.574Z","effectiveDate":"2026-07-15T23:30:55Z","sourceUrl":"https://github.com/advisories/GHSA-xg43-5579-qw6v","detail":{"severity":"medium","cve":null,"packages":"adawolfa/isdoc, adawolfa/isdoc, adawolfa/isdoc, adawolfa/isdoc","cvss":6.5}}]}