VDB
GCVE-110-COMPOSER-2026-042403
GCVE-110-COMPOSER-2026-042403
Advisory Published
[P-INSTALL-CURL] curl in install script (should not download during install) — matched: "build:docs": "curl --etag-save ./vendor/ag.etags --etag-compare ./vendor/ag.etags --create-dirs --remote-name --output-dir ./vendor/bin --no-progress-meter -- https://github.com/ApiGen/ApiGen/releases/latest/download/apigen.phar && php ./vendor/bin/apigen.phar --output docs -- src",
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| packagist | anthropic-ai/sdk | 0.55.0 (affected) | — |
Browse GCVE Records
3,321 records in the GCVE database · Updated October 7, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.