CVE-2024-8954
In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass authentication by providing any random value in the `x-api-key` header, thereby gaining unauthorized access to the server.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.85%
- CWE
- CWE-304
- Published
- 2025-03-20
- Last modified
- 2026-03-13
Affected products
- composiohq composiohq/composio
Weakness type
Related vulnerabilities
- CVE-2022-2302 — LENZE: Missing password verification in authorisation procedure
- CVE-2022-2821 — Missing Critical Step in Authentication in namelessmc/nameless
- CVE-2024-45764 — Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. A
- CVE-2024-12048 — IDOR Vulnerability in transformeroptimus/superagi
- CVE-2019-16766 — 2FA bypass in Wagtail through new device path
- CVE-2026-55957 — Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2024-2172 — Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
- CVE-2022-1065 — Multi Factor Authentication Bypass in various versions of Abacus ERP