PT-2026-56569 · Unknown · Composio Sdk

·

CVE-2026-59807

·

Published

2026-07-08

·

Updated

2026-07-10

CVSS v4.0

8.9

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Composio SDK versions prior to 0.2.32-beta.283
Description A path validation bypass allows attackers to read and exfiltrate sensitive files. This occurs due to a missing assertSafeFileUploadPath check in the readFileFromDisk() function within tool-file-uploads.ts. By using prompt injection, attackers can manipulate the file uploadable parameter to reference sensitive paths, such as SSH private keys, leading the CLI to upload credential files to storage controlled by the attacker.
Recommendations Update Composio SDK to version 0.2.32-beta.283 or later. As a temporary mitigation, restrict the use of the readFileFromDisk() function until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59807

Affected Products

Composio Sdk