CVE-2026-59807: Composiohq Composio
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can exploit prompt injection to manipulate file_uploadable parameters to reference sensitive paths such as SSH private keys, causing the CLI to upload credential files to attacker-controlled storage.
Affected products
- Composiohq Composio: before 0.2.32-beta.283 (fixed in 0.2.32-beta.283)
Published 2026-07-08. Last modified 2026-10-08.