Awaiting Analysis: kusanagi-composer Security Update

Synopsis

Issued 2026-04-15
Severity Awaiting Analysis
Updated Packages kusanagi-composer
Affected Products KUSANAGI 9, Business Edition, Security Edition

Description

An update for kusanagi-composer is now available.

Security fix(es):

  • * Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
  • * Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE information may not yet be available on those websites.

References

Updated packages listed below

This product uses the NVD API but is not endorsed or certified by the NVD.