Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Composio HIGH 7.5
CVE-2025-56427

Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir funct…

No fix yet
Fix from $1,950 2025-12-04
Composio CRITICAL 9.8
CVE-2024-8958

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation…

No fix yet
Fix from $2,300 2025-03-20
Composio HIGH 7.5
CVE-2024-8955

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co…

No fix yet
Fix from $1,950 2025-03-20
Composio CRITICAL 9.8
CVE-2024-8953

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This c…

No fix yet
Fix from $2,300 2025-03-20
Composio CRITICAL 9.8
CVE-2024-8954

In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability al…

No fix yet
Fix from $2,300 2025-03-20
Composio HIGH 7.5
CVE-2024-8952

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCR…

No fix yet
Fix from $1,950 2025-03-20
Composio MEDIUM 6.4
CVE-2024-53526

composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.

No fix yet
Fix from $1,600 2025-01-08
Composio HIGH 8.8
CVE-2024-8864

A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculat…

Fix: after 0.5.6
Fix from $1,950 2024-09-15