huntr.com
https://huntr.com/bounties/f1e0fdce-00d7-4261-a466-923062800b12 CVE-2024-8954
CRITICAL
Authentication Bypass in composiohq/composio
Record summary
CVE-2024-8954 has a selected CVSS score of 9.8 (critical).
Description
In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass authentication by providing any random value in the `x-api-key` header, thereby gaining unauthorized access to the server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
composiohq/composioBrowse composiohq / composiohq/composio | CVE List | Through latest | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-8954