PT-2026-65896 · Flytohub · Flyto-Core

CVE-2026-67429

·

Publicado

2026-07-29

·

Atualizado

2026-07-29

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output dir instead of validate path with env config and its FLYTO SANDBOX DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-67429

Produtos afetados

Flyto-Core