{"id":"CVE-2024-8953","aliases":["GHSA-5xg7-5662-8x7j","PYSEC-2026-1264"],"url":"https://o3.security/vulnerability/CVE-2024-8953","summary":"Unsafe eval usage in composiohq/composio","details":"In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.","published":"2025-03-20T10:10:56.507Z","modified":"2026-08-12T03:51:37.592106231Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"composio-core","fixedVersion":"0.5.43"}],"fix":{"url":"https://github.com/ComposioHQ/composio/commit/ed82fb45dc9fbd7f07c535c72bada871c158ae5f","label":"ComposioHQ/composio@ed82fb4"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/8203d721-e05f-4500-a5bc-c0bec980420c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8953.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8953"},{"type":"WEB","url":"https://github.com/ComposioHQ/composio/commit/ed82fb45dc9fbd7f07c535c72bada871c158ae5f"},{"type":"PACKAGE","url":"https://github.com/ComposioHQ/composio-js"},{"type":"WEB","url":"https://github.com/ComposioHQ/composio/blob/b932d99e67f0fe95f8a0a24be9352e3f99059bc3/python/composio/tools/local/mathematical/actions/calculator.py#L37"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.592106231Z"}}