ZeroHour

CVE-2024-8953

PoC
CVSS 3.1
9.8 critical
EPSS
1%p66
Published
()
Modified
Description

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.

Vendors
composio
Products
composio
Weakness
CWE-627, CWE-913
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.