Threat Advisory

Flyto Core Vulnerabilities Expose LLM API Secrets

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in flyto-core, a Python package that allows developers to build conversational AI models. These vulnerabilities could lead to cloud IAM credential theft and unauthorized internal service read and write operations.

CVE-2026-67429 (CVSS 10.0 — Critical): This vulnerability allows arbitrary file writes because the image.download module fails to restrict the output path, enabling an attacker to write malicious files anywhere on the system.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in flyto-core, a Python package that allows developers to build conversational AI models. These vulnerabilities could lead to cloud IAM credential theft and unauthorized internal service read and write operations.

CVE-2026-67429 (CVSS 10.0 — Critical): This vulnerability allows arbitrary file writes because the image.download module fails to restrict the output path, enabling an attacker to write malicious files anywhere on the system.[emaillocker id="1283"]

CVE-2026-67427 (CVSS 8.6 — High): The workflow engine expands ${env.VAR} without policy checks, allowing attackers to bypass the denylist and exfiltrate sensitive environment variables like API keys.

CVE-2026-67425 (CVSS 8.6 — High): The llm.chat module transmits the operator's API key to a caller-controlled base_url, allowing attackers to intercept credentials by supplying a malicious endpoint.

CVE-2026-67426(CVSS 9.3 — Critical): An authentication and SSRF vulnerability in Flyto Verification Service allows unauthenticated attackers to trigger callback requests, exfiltrate the FLYTO_RUNNER_SECRET, and access internal network resources.

CVE-2026-67428 (CVSS 8.5 — High): A server-side request forgery (SSRF) vulnerability in multiple Flyto Core HTTP modules allows authenticated attackers to access internal network resources and cloud metadata services by bypassing URL validation.

CVE-2026-67424 (CVSS 8.5 — High): A redirect validation flaw in Flyto Core allows attackers to bypass SSRF protections by using HTTP redirects to access internal network resources and cloud metadata services.

RECOMMENDATION:

We recommend you to update flyto-core to version 2.26.10 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu