MEDIUM6.4
PYSEC-2026-1268
Composio Command Execution vulnerability
Quick fix
PYSEC-2026-1268 — composio-julep: upgrade to the fixed version with the command below.
pip install --upgrade 'composio-julep>=0.6.9'Details
composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/composio-julep
Introduced in:
0.5.40Fixed in: 0.6.9Fix
pip install --upgrade 'composio-julep>=0.6.9'References
- https://nvd.nist.gov/vuln/detail/CVE-2024-53526[ADVISORY]
- https://github.com/ComposioHQ/composio/issues/1073[WEB]
- https://github.com/ComposioHQ/composio/pull/1107[WEB]
- https://github.com/ComposioHQ/composio/commit/f496f7fa776335ae7825cad2991c9b38923271fc[WEB]
- https://github.com/ComposioHQ/composio[PACKAGE]
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/claude/composio_claude/toolset.py#L156[WEB]
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/julep/composio_julep/toolset.py#L21[WEB]
- https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/openai/composio_openai/toolset.py#L184[WEB]
- https://pypi.org/project/composio-julep[PACKAGE]
- https://github.com/advisories/GHSA-8h93-28hg-fj84[ADVISORY]