Vulnerability Description
In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Composio | Composio | 0.4.3 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/8203d721-e05f-4500-a5bc-c0bec980420cExploit
- https://huntr.com/bounties/8203d721-e05f-4500-a5bc-c0bec980420cExploit
FAQ
What is CVE-2024-8953?
CVE-2024-8953 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted in...
How severe is CVE-2024-8953?
CVE-2024-8953 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-8953?
Check the references section above for vendor advisories and patch information. Affected products include: Composio Composio.