PT-2025-2965 · Composio · Composio

12End

·

Published

2025-01-08

·

Updated

2025-07-16

·

CVE-2024-53526

CVSS v3.1
6.4
VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

composio versions 0.5.40 and later

Description:

The issue allows for command execution in composio openai, composio claude, and composio julep via the `handle tool calls` function. This is due to improper user input sanitization, leading to arbitrary command injection.

Recommendations:

For composio versions 0.5.40 and later, consider disabling the `handle tool calls` function as a temporary workaround until a patch is available. Restrict access to the composio openai, composio claude, and composio julep modules to minimize the risk of exploitation. Avoid using unsanitized user input in the affected functions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-53526
GHSA-8H93-28HG-FJ84

Affected Products

Composio