In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Composio
Composio composio |
|
CPEs | cpe:2.3:a:composio:composio:0.4.3:*:*:*:*:*:*:* | |
Vendors & Products |
Composio
Composio composio |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution. | |
Title | Unrestricted File Write and Read in composiohq/composio | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T13:12:51.449Z
Reserved: 2024-09-17T19:26:51.080Z
Link: CVE-2024-8958

Updated: 2025-03-20T13:12:47.321Z

Status : Analyzed
Published: 2025-03-20T10:15:45.220
Modified: 2025-04-01T20:30:20.887
Link: CVE-2024-8958

No data.