VYPR
Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026

Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts

CVE-2026-59807

Description

Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can exploit prompt injection to manipulate file_uploadable parameters to reference sensitive paths such as SSH private keys, causing the CLI to upload credential files to attacker-controlled storage.

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.