package repository PHP recently encountered a critical remote codeexecution vulnerability .
Packagist is the default package host behind Composer and has over 435 million package installs. The vulnerability was discovered by security researcher Max Justicz, who found that the “Submit Package” package input field for submitting new PHP packages via the package repository homepage allows an attacker to execute a malicious command in the form of “$ “.

The expert pointed out that when a user provides a URL to Packagist they are removed from the login allowing a malicious user to execute any commands they wish.
Finally, Max Justicz warns users about the low level of security in Composer's infrastructure, which could open the doors to future attacks.
