Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6884 | In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function. |
Github GHSA |
GHSA-5xg7-5662-8x7j | Composio Eval Injection Vulnerability |
Tue, 01 Apr 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Composio
Composio composio |
|
| Weaknesses | CWE-913 | |
| CPEs | cpe:2.3:a:composio:composio:0.4.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Composio
Composio composio |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function. | |
| Title | Unsafe eval usage in composiohq/composio | |
| Weaknesses | CWE-627 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:10:22.095Z
Reserved: 2024-09-17T17:04:18.929Z
Link: CVE-2024-8953
Updated: 2025-03-20T18:10:17.719Z
Status : Analyzed
Published: 2025-03-20T10:15:44.843
Modified: 2025-04-01T20:30:28.420
Link: CVE-2024-8953
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA