From 71ab70d8477ae2425f5ab3b468481c406556542d Mon Sep 17 00:00:00 2001 From: Jordi Boggiano Date: Mon, 20 Dec 2021 14:27:34 +0100 Subject: [PATCH] Disable files autoloading for scripts to avoid untrusted code execution at runtime (#10373) --- src/Composer/EventDispatcher/EventDispatcher.php | 4 ---- 1 file changed, 4 deletions(-) diff --git a/src/Composer/EventDispatcher/EventDispatcher.php b/src/Composer/EventDispatcher/EventDispatcher.php index 88969e1d9..74ec3459d 100644 --- a/src/Composer/EventDispatcher/EventDispatcher.php +++ b/src/Composer/EventDispatcher/EventDispatcher.php @@ -509,10 +509,6 @@ class EventDispatcher $this->loader = $generator->createLoader($map, $this->composer->getConfig()->get('vendor-dir')); $this->loader->register(false); - foreach ($map['files'] as $fileIdentifier => $file) { - \Composer\Autoload\composerRequire($fileIdentifier, $file); - } - return $scripts[$event->getName()]; }