{"id":"PYSEC-2026-2428","summary":"Composio Command Execution vulnerability","details":"composio \u003e=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.","aliases":["CVE-2024-53526","GHSA-8h93-28hg-fj84","PYSEC-2026-1268","PYSEC-2026-2429"],"modified":"2026-07-13T16:43:11.568757035Z","published":"2026-07-13T14:36:33.146227Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53526"},{"type":"WEB","url":"https://github.com/ComposioHQ/composio/issues/1073"},{"type":"WEB","url":"https://github.com/ComposioHQ/composio/pull/1107"},{"type":"WEB","url":"https://github.com/ComposioHQ/composio/commit/f496f7fa776335ae7825cad2991c9b38923271fc"},{"type":"PACKAGE","url":"https://github.com/ComposioHQ/composio"},{"type":"WEB","url":"https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/claude/composio_claude/toolset.py#L156"},{"type":"WEB","url":"https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/julep/composio_julep/toolset.py#L21"},{"type":"WEB","url":"https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/openai/composio_openai/toolset.py#L184"},{"type":"PACKAGE","url":"https://pypi.org/project/composio-claude"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8h93-28hg-fj84"}],"affected":[{"package":{"name":"composio-claude","ecosystem":"PyPI","purl":"pkg:pypi/composio-claude"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.5.40"},{"fixed":"0.6.9"}]}],"versions":["0.5.40","0.5.41","0.5.42","0.5.43","0.5.44","0.5.45","0.5.46","0.5.47","0.5.48rc1","0.5.49","0.5.50","0.5.51","0.5.51rc1","0.5.52rc1","0.5.52rc2","0.6.0","0.6.0rc1","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/composio-claude/PYSEC-2026-2428.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"}]}