Skip to content

CVE-2025-67746

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
January 14, 2026
Last Seen
March 20, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Fedora has released updates for Composer version 2.9.3 to address a critical ANSI sequence injection vulnerability (CVE-2025-67746). The updates affect users managing PHP project dependencies and include fixes for the COMPOSER_NO_SECURITY_BLOCKING environment variable and issues with update commands...

An update for php-composer2 in openSUSE Leap 15.4 has been released to fix CVE-2025-67746, which involves ANSI control characters injection in terminal outputs of Composer commands. This vulnerability allows attackers to exploit remote sources to inject malicious control characters. The affected sys...

Public Exploits

Checking GitHub for proof-of-concept code…