CVE-2024-8955

CVSS 3.0 Score 6.8 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 643

Summary

CVE-2024-8955 is a Server-Side Request Forgery (SSRF) vulnerability affecting the composiohq/composio package, version v0.4.4. This issue enables attackers to read the contents of arbitrary files on the targeted system. The vulnerability is exploited through the BROWSERTOOL_GOTO_PAGE and BROWSERTOOL_GET_PAGE_DETAILS actions, allowing malicious actors to execute unauthorized requests, potentially leading to significant data exposure. It is crucial for users of this package to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share