Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hr7p-wg7r-hg9m | Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted |
Thu, 30 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flytohub
Flytohub flyto-core |
|
| Vendors & Products |
Flytohub
Flytohub flyto-core |
Wed, 29 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing a workflow parameter to bypass the default capability policy denylist for env.get and env.load_dotenv and exfiltrate secrets through allowed modules. This issue is fixed in version 2.26.6. | |
| Title | Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted | |
| Weaknesses | CWE-522 CWE-668 CWE-693 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-30T15:19:17.888Z
Reserved: 2026-07-29T15:02:20.413Z
Link: CVE-2026-67427
Updated: 2026-07-30T14:15:37.740Z
Status : Deferred
Published: 2026-07-29T19:16:51.913
Modified: 2026-07-30T19:27:35.030
Link: CVE-2026-67427
No data.
OpenCVE Enrichment
Updated: 2026-08-03T13:15:05Z
Github GHSA