---
id: CVE-2026-59807
title: >-
  Composio SDK before 0.2.32-beta.283 contains a path validation bypass
  vulnerability that allows attackers to read and exfiltrate sensitive files by
  exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk
  function with…
summary: >-
  Composio SDK before 0.2.32-beta.283 contains a path validation bypass
  vulnerability that allows attackers to read and exfiltrate sensitive files by
  exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk
  function with…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-73
vendor: ComposioHQ
product: composio
affected:
  - composio < 0.2.32-beta.283
published: '2026-07-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:24.603'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59807'
references:
  - url: >-
      https://github.com/ComposioHQ/composio/commit/fc17c37bf95b7ece5c038cb7e2ab7e3e4a064e3a
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ComposioHQ/composio/issues/3746'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ComposioHQ/composio/pull/3763'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ComposioHQ/composio/releases/tag/%40composio%2Fcli%400.2.32-beta.283
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/composio-sdk-beta-283-sensitive-file-upload-via-tool-file-uploads-ts
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ComposioHQ/composio/issues/3746'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-09T14:28:21.622630Z'
epss: 0.00467
epssPercentile: 0.38431
ingestedAt: '2026-10-08T16:52:14.697Z'
---

## Overview

Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can exploit prompt injection to manipulate file_uploadable parameters to reference sensitive paths such as SSH private keys, causing the CLI to upload credential files to attacker-controlled storage.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
