Security Advisory

CVE-2026-59807

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-08 19:43:51
Last updated 2026-07-09 14:28:25
Assigner VulnCheck
CVSS score 8.9
State PUBLISHED

Description

Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can exploit prompt injection to manipulate file_uploadable parameters to reference sensitive paths such as SSH private keys, causing the CLI to upload credential files to attacker-controlled storage.