HIGH7.5
PYSEC-2026-1262
ComposioHQ has a directory traversal vulnerability
Details
Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/composio
Introduced in:
0No fixed version published yet for composio (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-56427[ADVISORY]
- https://github.com/ComposioHQ/composio[PACKAGE]
- https://github.com/ComposioHQ/composio/blob/master/python/composio/server/api.py#L278[WEB]
- https://github.com/TOAST-Research/pocs/blob/main/composio/composio_1.md[WEB]
- https://pypi.org/project/composio[PACKAGE]
- https://github.com/advisories/GHSA-3mwv-j45g-vp3w[ADVISORY]