Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-43655

26
FAUCET Score

CVE-2023-43655 is a remote code execution vulnerability affecting Composer, a PHP dependency manager, specifically versions prior to 2.6.4, 2.2.22, and 1.10.27. This flaw occurs when a composer.phar file is publicly accessible on a web server and PHP's register_argc_argv setting is enabled, impacting various Debian and Fedora distributions. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the network with low privileges and no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score is 72/100, indicating significant risk. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness at this time.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.10.27CPE matchmatch criteria
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:*
>= 2.0.0, < 2.2.21CPE matchmatch criteria
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:*
>= 2.3.0, < 2.6.4CPE matchmatch criteria
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.4MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.5
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.39%
Probability of exploitation in next 30 days
EPSS Percentile
69.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0139 is in the 67th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

composerpatch availablevia ghsa
Product: composer/composerFixed in: 1.10.27
composerpatch availablevia ghsa
Product: composer/composerFixed in: 2.2.22
composerpatch availablevia ghsa
Product: composer/composerFixed in: 2.6.4
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-jm6m-4632-36hfhigh

Composer Remote Code Execution vulnerability via web-accessible composer.phar

Sep 29, 2023

References

github.com / composer/composer/commit/4fce14795aba98e40b6c4f5047305aba17a6120d
Patch
github.com / composer/composer/commit/955a48e6319c8962e5cd421b07c00ab3c728968c
Patch
github.com / composer/composer/commit/95e091c921037b7b6564942845e7b738f6b95c9c
Patch
github.com / composer/composer/security/advisories/GHSA-jm6m-4632-36hf
Vendor Advisory
lists.debian.org / debian-lts-announce/2024/03/msg00030.html
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/66H2WKFUO255T3BZTL72TNYJYH2XM5FG
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/7AWYAUZNH565NWPIKGEIYBWHYNM5JGAE
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/KFOPGPW2KS37O3KJWBRGTUWHTXCQXBS2
Mailing ListThird Party Advisory