CVE-2024-8953

CRITICAL

composiohq/composio <0.4.3 - RCE

Title source: llm
STIX 2.1

Description

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.

Scores

CVSS v3 9.8
EPSS 0.0027
EPSS Percentile 50.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-627 CWE-913
Status published
Products (2)
composio/composio 0.4.3
pypi/composio-core 0 - 0.5.43PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026