PT-2025-12252 · Composiohq · Composio
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-8955
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
composiohq/composio version v0.4.4
Description
A Server-Side Request Forgery (SSRF) issue exists, allowing an attacker to read the contents of any file in the system. This is achieved by exploiting the
BROWSERTOOL GOTO PAGE and BROWSERTOOL GET PAGE DETAILS actions.Recommendations
For composiohq/composio version v0.4.4, consider disabling the
BROWSERTOOL GOTO PAGE and BROWSERTOOL GET PAGE DETAILS actions as a temporary workaround until a patch is available.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Composio