CVE-2025-13828
Composer Package Installation Privilege Escalation
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A non-privileged user can install arbitrary packages, potentially executing malicious code and escalating privileges on systems that use composer for package management, even if composer-based updates are disabled. This could allow a low-privileged user to obtain higher privileges on the platform.