composiohq/composio
cpe:2.3:a:composio:composio:*:*:*:*:*:*:*
- 0.4.3
A vulnerability allowing arbitrary code execution has been identified in Composio version 0.4.3. The issue arises in the mathematical_calculator endpoint, where the eval() function is used to perform mathematical operations. This creates a risk of executing arbitrary code if untrusted input is provided to the eval() function.
Exploitation of this vulnerability could lead to arbitrary code execution on the server where Composio is running.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.