PT-2026-65892 · Flytohub · Flyto-Core
CVE-2026-67425
·
Publicado
2026-07-29
·
Atualizado
2026-07-29
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI API KEY and ANTHROPIC API KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.6.
Exploit
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Flyto-Core