PT-2025-2965 · Composio · Composio
12End
·
Published
2025-01-08
·
Updated
2025-07-16
·
CVE-2024-53526
6.4
Medium
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
composio versions 0.5.40 and later
Description:
The issue allows for command execution in composio openai, composio claude, and composio julep via the `handle tool calls` function. This is due to improper user input sanitization, leading to arbitrary command injection.
Recommendations:
For composio versions 0.5.40 and later, consider disabling the `handle tool calls` function as a temporary workaround until a patch is available. Restrict access to the composio openai, composio claude, and composio julep modules to minimize the risk of exploitation. Avoid using unsanitized user input in the affected functions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Weakness Enumeration
Related Identifiers
Affected Products
References · 13
- https://github.com/ComposioHQ/composio/issues/1073⭐ 25569 🔗 4401 · Vendor Advisory
- https://osv.dev/vulnerability/GHSA-8h93-28hg-fj84 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-53526 · Security Note
- https://github.com/ComposioHQ/composio⭐ 24501 🔗 4377 · Note
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/claude/composio_claude/toolset.py#L156⭐ 14393 🔗 4240 · Note
- https://github.com/ComposioHQ/composio/pull/1107⭐ 14393 🔗 4240 · Note
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/julep/composio_julep/toolset.py#L21⭐ 14393 🔗 4240 · Note
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/openai/composio_openai/toolset.py#L184⭐ 14393 🔗 4240 · Note
- https://github.com/ComposioHQ/composio/commit/f496f7fa776335ae7825cad2991c9b38923271fc⭐ 14393 🔗 4240 · Note
- https://t.me/cvedetector/14728 · Telegram Post
- https://twitter.com/CVEnew/status/1877070631046426965 · Twitter Post
- https://t.me/cvenotify/129105 · Telegram Post
- https://twitter.com/0x3n0/status/1879420669022310861 · Twitter Post