CVE-2024-8952 Information
Mar 21, 2025
cve
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2 specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. This vulnerability allows an attacker to read files access AWS metadata and interact with local services on the system.
Reference
https://huntr.com/bounties/d1acdd38-10d7-45df-9df0-9fc71f0e1c2a https://huntr.com/bounties/d1acdd38-10d7-45df-9df0-9fc71f0e1c2a
Share on: