Composio is an integration and workflow automation platform whose vulnerability profile, while narrow in product scope, skews strongly toward critical-severity outcomes. The recurring weakness classes—server-side request forgery, dynamic code evaluation, code injection, and exposure of sensitive information—reflect the inherent risks of a system designed to orchestrate and chain external services and dynamically execute user-supplied logic. Defenders should treat this vendor's advisories as high-priority given the severity tendency and the platform's role in connecting multiple downstream systems; live exploitation status and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Composio over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8958CRITICAL In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can | Mar 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-56427HIGH Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function. | Dec 4, 2025 | 7.5 | 26 | NO | NO |
CVE-2024-8954CRITICAL In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass auth | Mar 20, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-8953CRITICAL In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execu | Mar 20, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-8864HIGH A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the file python/composio/ | Sep 15, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-8955HIGH A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the contents of any file in the syste | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-8952HIGH A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. T | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-53526MEDIUM composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function. | Jan 8, 2025 | 6.4 | 17 | NO | NO |
CVE-2024-8865MEDIUM A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file composio\server\api.py. The mani | Sep 15, 2024 | 4.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Composio.
Media articles that mention a CVE ID that affects a product developed by Composio — matched by CVE ID, not by vendor name.