In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.
CVE ID: CVE-2024-8958
CVSS Base Severity: HIGH
CVSS Base Score: 7.2
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vendor: composiohq
Product: composiohq/composio
EPSS Score: 0.35% (probability of being exploited)
EPSS Percentile: 56.26% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)