PT-2026-65893 · Flytohub · Flyto-Core

CVE-2026-67426

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback url for an outbound POST with X-Internal-Key: $FLYTO RUNNER SECRET while bypassing target allowed, allowing unauthenticated SSRF and runner secret exfiltration. This issue is fixed in version 2.26.7.

Exploit

Fix

Insufficiently Protected Credentials

Missing Authentication

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67426

Affected Products

Flyto-Core