PT-2025-12249 · Composio · Composio

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-8952

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions composiohq/composio version v0.4.2
Description A Server-Side Request Forgery (SSRF) issue exists, specifically in the "/api/actions/execute/WEBTOOL SCRAPE WEBSITE CONTENT" endpoint. This allows an attacker to read files, access AWS metadata, and interact with local services on the system.
Recommendations For version v0.4.2, consider disabling access to the "/api/actions/execute/WEBTOOL SCRAPE WEBSITE CONTENT" endpoint until a patch is available. Restrict interactions with local services and limit access to AWS metadata to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8952
GHSA-QVG9-VP87-H3HR

Affected Products

Composio