VDB
Sign up
MEDIUM6.8

PYSEC-2026-1263

composio allows Server-Side Request Forgery (SSRF) in BROWSERTOOL

Details

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the contents of any file in the system by exploiting the BROWSERTOOL_GOTO_PAGE and BROWSERTOOL_GET_PAGE_DETAILS actions.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/composio-core
Introduced in: 0

No fixed version published yet for composio-core (pip). Pin to a known-safe version or switch to an alternative.

References