PT-2025-12253 · Composiohq · Composio

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-8958

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions composiohq/composio version 0.4.3
Description The issue is related to an unrestricted file write and read vulnerability in the filetools actions. This is due to improper validation of file paths, allowing an attacker to read and write files anywhere on the server. This could potentially lead to privilege escalation or remote code execution.
Recommendations For composiohq/composio version 0.4.3, consider restricting access to the filetools actions until a patch is available. As a temporary workaround, implement proper validation of file paths to prevent unauthorized file access.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8958

Affected Products

Composio