Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jx74-cqjv-2c67 | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration |
Thu, 30 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flytohub
Flytohub flyto-core |
|
| Vendors & Products |
Flytohub
Flytohub flyto-core |
Wed, 29 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback_url for an outbound POST with X-Internal-Key: $FLYTO_RUNNER_SECRET while bypassing target_allowed, allowing unauthenticated SSRF and runner secret exfiltration. This issue is fixed in version 2.26.7. | |
| Title | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration | |
| Weaknesses | CWE-306 CWE-522 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-29T19:05:05.601Z
Reserved: 2026-07-29T15:02:20.413Z
Link: CVE-2026-67426
Updated: 2026-07-29T19:04:03.775Z
Status : Deferred
Published: 2026-07-29T19:16:51.770
Modified: 2026-07-30T16:41:25.650
Link: CVE-2026-67426
No data.
OpenCVE Enrichment
Updated: 2026-08-03T13:15:05Z
Github GHSA