Composio Arbitrary Code Execution Vulnerability via Unsafe eval() Function in Mathematical Calculator Endpoint

Vulnerability

A vulnerability allowing arbitrary code execution has been identified in Composio version 0.4.3. The issue arises in the mathematical_calculator endpoint, where the eval() function is used to perform mathematical operations. This creates a risk of executing arbitrary code if untrusted input is provided to the eval() function.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the server where Composio is running.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.