composioGHSA-3mwv-j45g-vp3w
ComposioHQ has a directory traversal vulnerability
Medium7.5CVE-2025-56427 · Published Dec 4, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| composio PyPI | <= 0.7.20 | No fix yet |
Details and references
Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.