← Vulnerability feed

Vulnerability record · CVE-2024-8952 · published 20 March 2025

CVE-2024-8952: Composio server-side request forgery (ssrf) vulnerability

Composio · Composio

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. This vulnerability allows an attacker to read files, access AWS metadata, and interact with local services on the system.

7.5 CVSS 3.1 High EPSS 0.72% · top 48.0% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score
0.72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. This vulnerability allows an attacker to read files, access AWS metadata, and interact with local services on the system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8952 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-8958Composio unrestricted file upload vulnerabilityIn composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation…EPSS 1.4%9.8CVE-2024-8953Composio improper control of dynamically-managed code vulnerabilityIn composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This c…EPSS 1.2%9.8CVE-2024-8954Composio vulnerabilityIn composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability al…EPSS 0.87%7.5CVE-2025-56427Composio information exposure vulnerabilityDirectory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir funct…EPSS 0.89%7.5CVE-2024-8955Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co…EPSS 0.73%6.4CVE-2024-53526Composio command injection vulnerabilitycomposio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.EPSS 0.59%5.1CVE-2024-8864Composio code injection vulnerabilityA vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculat…EPSS 0.83%5.1CVE-2024-8865Composio path traversal vulnerabilityA vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file c…EPSS 0.87%

Source: NIST National Vulnerability Database (record CVE-2024-8952), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.