High severity7.5OSV Advisory· Published Dec 4, 2025· Updated Jun 17, 2026
CVE-2025-56427
CVE-2025-56427
Description
Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
composioPyPI | <= 0.7.20 | — |
Affected products
3- Range: 0.5.0+post.1, js-v-0.4.8, js-v-0.5.0, …
Patches
Vulnerability mechanics
References
4- github.com/TOAST-Research/pocs/blob/main/composio/composio_1.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-3mwv-j45g-vp3wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-56427ghsaADVISORY
- github.com/ComposioHQ/composio/blob/master/python/composio/server/api.pynvdBroken LinkWEB
News mentions
0No linked articles in our index yet.