CVE-2024-8952

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 918

Summary

CVE-2024-8952 is a newly disclosed Server-Side Request Forgery (SSRF) vulnerability impacting the composiohq/composio package, specifically version v0.4.2. This weakness lies within the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. An attacker who successfully exploits this vulnerability can read local files, access AWS metadata, and interact with other services on the compromised system. This poses a significant risk to the confidentiality and integrity of the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share