CVE-2024-8952

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
20/03/2025
Last modified:
01/04/2025

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. This vulnerability allows an attacker to read files, access AWS metadata, and interact with local services on the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:composio:composio:0.4.2:*:*:*:*:*:*:*