← Vulnerability feed

Vulnerability record · CVE-2024-8865 · published 15 September 2024

CVE-2024-8865: Composio path traversal vulnerability

Composio · Composio

A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file composio\server\api.py. The manipulation of the argument file leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5.1 CVSS 4.0 Medium EPSS 0.87% · top 42.8% CWE-22 · Path traversal
5.1CVSS 4.0 base score, v2 2.7
0.87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file composio\server\api.py. The manipulation of the argument file leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://rumbling-slice-eb0.notion.site/There-is-an-arbitrary-file-read-vulnerability-at-api-download-in-composiohq-compo Exploit
https://vuldb.com/?ctiid.277502 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.277502 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?submit.403206 Third Party AdvisoryVDB Entry

Track CVE-2024-8865 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-8958Composio unrestricted file upload vulnerabilityIn composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation…EPSS 1.4%9.8CVE-2024-8953Composio improper control of dynamically-managed code vulnerabilityIn composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This c…EPSS 1.2%9.8CVE-2024-8954Composio vulnerabilityIn composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability al…EPSS 0.87%7.5CVE-2025-56427Composio information exposure vulnerabilityDirectory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir funct…EPSS 0.89%7.5CVE-2024-8955Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co…EPSS 0.73%7.5CVE-2024-8952Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCR…EPSS 0.72%6.4CVE-2024-53526Composio command injection vulnerabilitycomposio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.EPSS 0.59%5.1CVE-2024-8864Composio code injection vulnerabilityA vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculat…EPSS 0.83%

Source: NIST National Vulnerability Database (record CVE-2024-8865), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.