MEDIUM6.8
PYSEC-2026-1267
composio Server-Side Request Forgery (SSRF) vulnerability
Details
A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. This vulnerability allows an attacker to read files, access AWS metadata, and interact with local services on the system.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/composio-core
Introduced in:
0No fixed version published yet for composio-core (pip). Pin to a known-safe version or switch to an alternative.