CVE-2024-8954: Authentication Bypass in composiohq/composio

9.8 CVSS

Description

In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass authentication by providing any random value in the `x-api-key` header, thereby gaining unauthorized access to the server.

Classification

CVE ID: CVE-2024-8954

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem Types

CWE-304 Missing Critical Step in Authentication

Affected Products

Vendor: composiohq

Product: composiohq/composio

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.09% (probability of being exploited)

EPSS Percentile: 26.31% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-8954
https://huntr.com/bounties/f1e0fdce-00d7-4261-a466-923062800b12

Timeline