PT-2026-65893 · Flytohub · Flyto-Core
CVE-2026-67426
·
Publicado
2026-07-29
·
Atualizado
2026-07-29
CVSS v3.1
9.3
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback url for an outbound POST with X-Internal-Key: $FLYTO RUNNER SECRET while bypassing target allowed, allowing unauthenticated SSRF and runner secret exfiltration. This issue is fixed in version 2.26.7.
Exploit
Correção
Insufficiently Protected Credentials
Missing Authentication
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Flyto-Core