PT-2026-65893 · Flytohub · Flyto-Core

CVE-2026-67426

·

Publicado

2026-07-29

·

Atualizado

2026-07-29

CVSS v3.1

9.3

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback url for an outbound POST with X-Internal-Key: $FLYTO RUNNER SECRET while bypassing target allowed, allowing unauthenticated SSRF and runner secret exfiltration. This issue is fixed in version 2.26.7.

Exploit

Correção

Insufficiently Protected Credentials

Missing Authentication

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-67426

Produtos afetados

Flyto-Core