CVE-2024-8953
published 2025-03-20CVE-2024-8953: In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.10%
61.6th percentile
In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| composio | composio | — | — |
| composiohq | composiohq_composio | unspecified – latest | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Composio Eval Injection Vulnerability
osv·2025-03-20
CVE-2024-8953 [HIGH] Composio Eval Injection Vulnerability
Composio Eval Injection Vulnerability
In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.
GHSA
Composio Eval Injection Vulnerability
ghsa·2025-03-20
CVE-2024-8953 [HIGH] CWE-627 Composio Eval Injection Vulnerability
Composio Eval Injection Vulnerability
In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.
Red Hat
unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
vendor_redhat·2024-02-13·CVSS 8.0
CVE-2024-1488 [HIGH] CWE-276 unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-20
Published