CVE-2026-59807 Details
Description
Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can exploit prompt injection to manipulate file_uploadable parameters to reference sensitive paths such as SSH private keys, causing the CLI to upload credential files to attacker-controlled storage.
A path validation bypass vulnerability has been identified in Composio SDK versions prior to 0.2.32-beta.283. This vulnerability allows attackers to read and exfiltrate sensitive files by exploiting a missing validation check in the file upload functionality of the CLI. The issue arises when the CLI is used to execute tools that require file attachments, such as emails via the Gmail API. Attackers can manipulate the file parameters to reference sensitive paths, like SSH private keys, leading to unauthorized upload of credential files to an attacker-controlled location.
Users can update to Composio SDK version 0.2.32-beta.283 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ComposioHQ/composio/issues/3746 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/ComposioHQ/composio/commit/fc17c37bf95b7ece5c038cb7e2ab7e3e4a064e3a | [email protected] | Source CodeVendor |
| https://github.com/ComposioHQ/composio/issues/3746 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/ComposioHQ/composio/pull/3763 | [email protected] | Issue TrackingVendor |
| https://github.com/ComposioHQ/composio/releases/tag/%40composio%2Fcli%400.2.32-beta.283 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/composio-sdk-beta-283-sensitive-file-upload-via-tool-file-uploads-ts | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Composio | < 0.2.32-beta.283 (semver) |
CPE
Remediation
| |
| Composio CLI | < 0.2.32-beta.283 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |
Volerion