Skip to content
composioGHSA-3mwv-j45g-vp3w

ComposioHQ has a directory traversal vulnerability

Medium7.5CVE-2025-56427 · Published Dec 4, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
composio
PyPI
<= 0.7.20No fix yet
Details and references

Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200, CWE-22
Also known as
CVE-2025-56427, PYSEC-2026-1262

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.