CVE-2024-8953

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/03/2025
Last modified:
01/04/2025

Description

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:composio:composio:0.4.3:*:*:*:*:*:*:*