PT-2025-12252 · Composiohq · Composio

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-8955

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions composiohq/composio version v0.4.4
Description A Server-Side Request Forgery (SSRF) issue exists, allowing an attacker to read the contents of any file in the system. This is achieved by exploiting the BROWSERTOOL GOTO PAGE and BROWSERTOOL GET PAGE DETAILS actions.
Recommendations For composiohq/composio version v0.4.4, consider disabling the BROWSERTOOL GOTO PAGE and BROWSERTOOL GET PAGE DETAILS actions as a temporary workaround until a patch is available.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8955
GHSA-38MG-WM59-G64X

Affected Products

Composio