Vulnerability Description
In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Composio | Composio | 0.4.3 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/e152b094-0593-428e-b813-068d2390ce68Exploit
- https://huntr.com/bounties/e152b094-0593-428e-b813-068d2390ce68Exploit
FAQ
What is CVE-2024-8958?
CVE-2024-8958 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write file...
How severe is CVE-2024-8958?
CVE-2024-8958 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-8958?
Check the references section above for vendor advisories and patch information. Affected products include: Composio Composio.