Home

Description

Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.

PUBLISHED Reserved 2025-08-17 | Published 2025-12-04 | Updated 2025-12-05 | Assigner mitre

References

github.com/...Research/pocs/blob/main/composio/composio_1.md exploit

github.com/...osio/blob/master/python/composio/server/api.py

github.com/...Research/pocs/blob/main/composio/composio_1.md

cve.org (CVE-2025-56427)

nvd.nist.gov (CVE-2025-56427)