Synopsis
| Issued | 2026-04-15 |
| Severity | Awaiting Analysis |
| Updated Packages | kusanagi-composer |
| Affected Products | KUSANAGI 9, Business Edition, Security Edition |
Description
An update for kusanagi-composer is now available.
Security fix(es):
- * Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
- * Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE information may not yet be available on those websites.