Описание
Composio Command Execution vulnerability
composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-53526
- https://github.com/ComposioHQ/composio/issues/1073
- https://github.com/ComposioHQ/composio/pull/1107
- https://github.com/ComposioHQ/composio/commit/f496f7fa776335ae7825cad2991c9b38923271fc
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/claude/composio_claude/toolset.py#L156
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/julep/composio_julep/toolset.py#L21
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/openai/composio_openai/toolset.py#L184
Пакеты
Наименование
composio-claude
pip
Затронутые версииВерсия исправления
>= 0.5.40, < 0.6.9
0.6.9
Наименование
composio-openai
pip
Затронутые версииВерсия исправления
>= 0.5.40, < 0.6.9
0.6.9
Наименование
composio-julep
pip
Затронутые версииВерсия исправления
>= 0.5.40, < 0.6.9
0.6.9
Связанные уязвимости
CVSS3: 6.4
nvd
около 1 года назад
composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.