Multiple vulnerabilities have been identified in flyto-core, a Python package that allows developers to build conversational AI models. These vulnerabilities could lead to cloud IAM credential theft and unauthorized internal service read and write operations.
CVE-2026-67429 (CVSS 10.0 — Critical): This vulnerability allows arbitrary file writes because the image.download module fails to restrict the output path, enabling an attacker to write malicious files anywhere on the system.[/subscribe_to_unlock_form]
Multiple vulnerabilities have been identified in flyto-core, a Python package that allows developers to build conversational AI models. These vulnerabilities could lead to cloud IAM credential theft and unauthorized internal service read and write operations.
CVE-2026-67429 (CVSS 10.0 — Critical): This vulnerability allows arbitrary file writes because the image.download module fails to restrict the output path, enabling an attacker to write malicious files anywhere on the system.[emaillocker id="1283"]
CVE-2026-67427 (CVSS 8.6 — High): The workflow engine expands ${env.VAR} without policy checks, allowing attackers to bypass the denylist and exfiltrate sensitive environment variables like API keys.
CVE-2026-67425 (CVSS 8.6 — High): The llm.chat module transmits the operator's API key to a caller-controlled base_url, allowing attackers to intercept credentials by supplying a malicious endpoint.
CVE-2026-67426(CVSS 9.3 — Critical): An authentication and SSRF vulnerability in Flyto Verification Service allows unauthenticated attackers to trigger callback requests, exfiltrate the FLYTO_RUNNER_SECRET, and access internal network resources.
CVE-2026-67428 (CVSS 8.5 — High): A server-side request forgery (SSRF) vulnerability in multiple Flyto Core HTTP modules allows authenticated attackers to access internal network resources and cloud metadata services by bypassing URL validation.
CVE-2026-67424 (CVSS 8.5 — High): A redirect validation flaw in Flyto Core allows attackers to bypass SSRF protections by using HTTP redirects to access internal network resources and cloud metadata services.
We recommend you to update flyto-core to version 2.26.10 or later.
The following reports contain further technical details:
[/emaillocker]