Researchers Report Supply Chain Vulnerability in Packagist PHP Repository

Tracked as CVE-2022-24828 (CVSS score: 8.8), the issue has been described as a case of command injection and is linked to another similar Composer bug (CVE-2021-29472) that came to light in April 2021, suggesting an inadequate patch.
Source: cyware.com