VDB
Sign up
MEDIUM6.4

PYSEC-2026-1268

Composio Command Execution vulnerability

Quick fix

PYSEC-2026-1268 — composio-julep: upgrade to the fixed version with the command below.

pip install --upgrade 'composio-julep>=0.6.9'

Details

composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/composio-julep
Introduced in: 0.5.40Fixed in: 0.6.9
Fixpip install --upgrade 'composio-julep>=0.6.9'

References