In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6883 In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Apr 2025 06:00:00 +0900

Type Values Removed Values Added
First Time appeared Composio
Composio composio
CPEs cpe:2.3:a:composio:composio:0.4.3:*:*:*:*:*:*:*
Vendors & Products Composio
Composio composio
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 20 Mar 2025 23:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 19:15:00 +0900

Type Values Removed Values Added
Description In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
Title Unrestricted File Write and Read in composiohq/composio
Weaknesses CWE-434
References
Metrics cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-03-20T13:12:51.449Z

Reserved: 2024-09-17T19:26:51.080Z

Link: CVE-2024-8958

cve-icon Vulnrichment

Updated: 2025-03-20T13:12:47.321Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:45.220

Modified: 2025-04-01T20:30:20.887

Link: CVE-2024-8958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses