In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Composio
Composio composio |
|
| CPEs | cpe:2.3:a:composio:composio:0.4.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Composio
Composio composio |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution. | |
| Title | Unrestricted File Write and Read in composiohq/composio | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:16.677Z
Updated: 2025-03-20T13:12:51.449Z
Reserved: 2024-09-17T19:26:51.080Z
Link: CVE-2024-8958
Updated: 2025-03-20T13:12:47.321Z
Status : Analyzed
Published: 2025-03-20T10:15:45.220
Modified: 2025-04-01T20:30:20.887
Link: CVE-2024-8958
No data.