#VU125893 Improper input validation in composer - CVE-2025-67746
Published: April 14, 2026
composer
getcomposer.org
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper neutralization of terminal control sequences in terminal output handling when processing data from remote sources. A remote attacker can inject ANSI control characters to cause a denial of service.
The issue may also mangle terminal output and lead to user confusion.