PT-2025-12250 · Composio · Composio

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-8953

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions composiohq/composio version 0.4.3
Description The issue concerns the use of the unsafe eval() function in the "mathematical calculator" endpoint to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.
Recommendations For composiohq/composio version 0.4.3, consider disabling the mathematical calculator endpoint until a patch is available that replaces the eval() function with a safer alternative. Restrict access to this endpoint to minimize the risk of exploitation. Avoid passing untrusted input to the eval() function in the mathematical calculator endpoint.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8953
GHSA-5XG7-5662-8X7J

Affected Products

Composio