In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
History

Thu, 20 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
Title Unrestricted File Write and Read in composiohq/composio
Weaknesses CWE-434
References
Metrics cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:11:16.677Z

Updated: 2025-03-20T13:12:51.449Z

Reserved: 2024-09-17T19:26:51.080Z

Link: CVE-2024-8958

cve-icon Vulnrichment

Updated: 2025-03-20T13:12:47.321Z

cve-icon NVD

Status : Received

Published: 2025-03-20T10:15:45.220

Modified: 2025-03-20T14:15:22.220

Link: CVE-2024-8958

cve-icon Redhat

No data.