CVE-2024-8958

CRITICAL

Composio - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0127
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
composio/composio 0.4.3
Published Mar 20, 2025
Tracked Since Feb 18, 2026