CVE-2024-8958

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
20/03/2025
Last modified:
01/04/2025

Description

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:composio:composio:0.4.3:*:*:*:*:*:*:*