Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-59807: Composio SDK path validation bypass enables credential file exfiltration

Composio SDK versions before 0.2.32-beta.283 lack an assertSafeFileUploadPath check in the readFileFromDisk function of tool-file-uploads.ts, letting attackers use prompt injection to manipulate file_uploadable parameters and make the CLI upload sensitive files such as SSH private keys to attacker-controlled storage. The issue was fixed in release 0.2.32-beta.283.

Disclosed 8 July 2026 · Record updated 13 September 2026

Impact

Attackers could read and exfiltrate sensitive local files, including SSH private keys and other credential files, by uploading them to attacker-controlled storage.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-59807