CVE-2024-8953

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 913
CWE ID 627

Summary

CVE-2024-8953 is a newly disclosed vulnerability affecting the mathematical_calculator endpoint in Composio, a software solution by composiohq, version 0.4.3. The issue arises due to the use of the unsafe eval() function for mathematical operations in this endpoint. This function can execute arbitrary code when presented with untrusted user input, posing a significant security risk if the endpoint receives malicious input. Attackers can leverage this flaw to gain unauthorized access, manipulate data, or cause other potential harm to affected systems. It is strongly recommended that users update to the latest version of Composio to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share