← Vulnerability feed

Vulnerability record · CVE-2024-8954 · published 20 March 2025

CVE-2024-8954: Composio vulnerability

Composio · Composio

In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass authentication by providing any random value in the `x-api-key` header, thereby gaining unauthorized access to the server.

9.8 CVSS 3.0 Critical EPSS 0.87% · top 42.9% CWE-304 · CWE-304
9.8CVSS 3.0 base score
0.87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass authentication by providing any random value in the `x-api-key` header, thereby gaining unauthorized access to the server.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8954 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-8958Composio unrestricted file upload vulnerabilityIn composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation…EPSS 1.4%9.8CVE-2024-8953Composio improper control of dynamically-managed code vulnerabilityIn composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This c…EPSS 1.2%7.5CVE-2025-56427Composio information exposure vulnerabilityDirectory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir funct…EPSS 0.89%7.5CVE-2024-8955Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co…EPSS 0.73%7.5CVE-2024-8952Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCR…EPSS 0.72%6.4CVE-2024-53526Composio command injection vulnerabilitycomposio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.EPSS 0.59%5.1CVE-2024-8864Composio code injection vulnerabilityA vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculat…EPSS 0.83%5.1CVE-2024-8865Composio path traversal vulnerabilityA vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file c…EPSS 0.87%

Source: NIST National Vulnerability Database (record CVE-2024-8954), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.