VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-59807

CVE-2026-59807: Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex

Published Jul 8, 2026 CVSS 8.9

Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can exploit prompt injection to manipulate file_uploadable parameters to reference sensitive paths such as SSH private keys, causing the CLI to upload credential files to attacker-controlled storage.

Affected AI Products

prompt injection
Get the weekly digest. Every Monday: top AI security stories of the week. Free.