← Vulnerability feed

Vulnerability record · CVE-2024-8864 · published 15 September 2024

CVE-2024-8864: Composio code injection vulnerability

Composio · Composio

A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the file python/composio/tools/local/mathematical/actions/calculator.py. The manipulation leads to code injection. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5.1 CVSS 4.0 Medium EPSS 0.83% · top 44.2% CWE-94 · Code injection
5.1CVSS 4.0 base score, v2 5.2
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the file python/composio/tools/local/mathematical/actions/calculator.py. The manipulation leads to code injection. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://rumbling-slice-eb0.notion.site/Composio-s-Local-tools-Mathematical-has-a-code-injection-risk-in-composiohq-compo ExploitThird Party Advisory
https://vuldb.com/?ctiid.277501 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.277501 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.403204 Third Party AdvisoryVDB Entry

Track CVE-2024-8864 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-8958Composio unrestricted file upload vulnerabilityIn composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation…EPSS 1.4%9.8CVE-2024-8953Composio improper control of dynamically-managed code vulnerabilityIn composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This c…EPSS 1.2%9.8CVE-2024-8954Composio vulnerabilityIn composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability al…EPSS 0.87%7.5CVE-2025-56427Composio information exposure vulnerabilityDirectory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir funct…EPSS 0.89%7.5CVE-2024-8955Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co…EPSS 0.73%7.5CVE-2024-8952Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCR…EPSS 0.72%6.4CVE-2024-53526Composio command injection vulnerabilitycomposio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.EPSS 0.59%5.1CVE-2024-8865Composio path traversal vulnerabilityA vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file c…EPSS 0.87%

Source: NIST National Vulnerability Database (record CVE-2024-8864), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.