CVE-2024-53526

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 8, 2025
Updated: Jan 31, 2025
CWE ID 77

Summary

CVE-2024-53526 is a newly disclosed vulnerability that impacts the composio library, specifically versions greater than or equal to 0.5.40. The issue resides in the functions handle_tool_calls in composio_openai, composio_claude, and composio_julep. An attacker can exploit this Command Execution vulnerability to execute arbitrary system commands, posing a significant risk to the security of affected systems. Users are advised to upgrade to the latest version of composio as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share