CVE-2026-59807: Composio SDK path validation bypass enables credential file exfiltration
Composio SDK versions before 0.2.32-beta.283 lack an assertSafeFileUploadPath check in the readFileFromDisk function of tool-file-uploads.ts, letting attackers use prompt injection to manipulate file_uploadable parameters and make the CLI upload sensitive files such as SSH private keys to attacker-controlled storage. The issue was fixed in release 0.2.32-beta.283.
Disclosed 8 July 2026 · Record updated 13 September 2026
Impact
Attackers could read and exfiltrate sensitive local files, including SSH private keys and other credential files, by uploading them to attacker-controlled storage.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-59807
