CVE-2026-84856: rowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of service

Published Sep 2, 2026
·
Updated

A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook Endpoint. The manipulation results in denial of service. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 0.9.2 is sufficient to resolve this issue. Upgrading the affected component is recommended. The legacy Next.js app was deleted at 0.9.2 rather than patched, leaving no security control behind.

Affected Software

1 affected component
rowboatlabs rowboat<=0.9.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rowboatlabs rowboat Composio Webhook Endpoint (apps/rowboat/app/api/composio/webhook/route.ts) to a version that resolves this vulnerability.

    Fixed in 0.9.2

Event History

Sep 2, 2026
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments of rowboatlabs rowboat through version 0.9.1 that include the legacy Next.js Composio Webhook Endpoint are affected. The issue can be exploited remotely.

2

What does an attacker need to exploit it?

No privileges or user interaction are required. The available information identifies request.text/req.json handling in the Composio webhook route as the affected functionality, and a public exploit is available.

3

Does upgrading remove the affected endpoint?

Yes. Version 0.9.2 resolves the issue by deleting the legacy Next.js application rather than patching the route, so the affected endpoint is no longer present.

4

How can I determine whether my deployment is affected?

Check the deployed rowboat version and whether it includes apps/rowboat/app/api/composio/webhook/route.ts in the legacy Next.js application. Versions up to 0.9.1 are affected; version 0.9.2 removes that application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203