Impact
The advisory identifies an input‑validation weakness (CWE‑20) in Composer as used within Drupal projects. The description stops after "allows .", so the precise behavior that is compromised is not disclosed. The primary risk is that manipulated input could alter the way Composer processes configuration or dependency data. The impact is therefore limited to the integrity of Composer input handling and the configuration they produce, but the extent of any further damage is unknown.
Affected Systems
All Drupal Composer instances are potentially vulnerable, encompassing every Composer version (indicated by *.*) used within Drupal projects. This includes deployment systems, continuous‑integration pipelines, and any local environments that run Composer commands during Drupal build or deployment.
Risk and Exploitability
The EPSS score is less than 1 %, and the vulnerability is not listed in CISA’s KEV catalog, implying no documented public exploits. The CVSS score of 5.9‑severity range. Based on the description of an input‑validation flaw, an attacker would most likely need a command. Local or deployment‑time access to the environment is therefore inferred as required; no remote exploitation avenue is indicated. Because the exact conditions are unspecified, overall risk remains moderate.
OpenCVE Enrichment