CVE-2024-8953

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-8953
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8953.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-8953
Aliases
Published
2025-03-20T10:15:44Z
Modified
2025-04-02T08:42:59.998427Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.

References

Affected packages

Git / github.com/composiohq/composio

Affected ranges

Type
GIT
Repo
https://github.com/composiohq/composio
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v0.*

v0.2.16
v0.2.17
v0.2.18
v0.2.19
v0.2.20
v0.2.21
v0.2.22
v0.2.23
v0.3.0
v0.3.1
v0.3.10
v0.3.11
v0.3.12
v0.3.13
v0.3.14
v0.3.15
v0.3.16
v0.3.17
v0.3.18
v0.3.19
v0.3.2
v0.3.20
v0.3.21
v0.3.22
v0.3.23
v0.3.24
v0.3.25
v0.3.26
v0.3.28
v0.3.29
v0.3.3
v0.3.30
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.7.1
v0.3.8
v0.3.9
v0.3.9-rc.1
v0.3.9-rc.2
v0.3.9-rc.3
v0.3.9rc4
v0.4.0
v0.4.1
v0.4.2
v0.4.3