flyto-core
PyPI8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting flyto-corepage 1 of 1
- CVE-2026-55786HIGHCVSS 8.4EG 8.4✓ Fixed in 2.26.42026-07-06
vulnerable: 2.26.2, 2.26.3
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module` ## Unauthenticated Command Execution via HTTP MCP `execute_module` ### Summary The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON…
- CVE-2026-55787HIGHCVSS 7.1EG 7.1✓ Fixed in 2.26.32026-07-06
vulnerable: 1.0.0 ... 2.9.0 (213 versions)
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf ## Summary `flyto-core`'s SSRF protection (`validate_url_ssrf` / `is_private_ip` in `src/core/utils.py`) blocks private and …
- CVE-2026-67424HIGHCVSS 8.5EG 8.5✓ Fixed in 2.26.72026-07-29
vulnerable: 1.0.0 ... 2.9.0 (216 versions)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/modules/atomic/http/get.py, src/core/modules/atomic/http/request.py, and src/cor…
- CVE-2026-67425HIGHCVSS 8.6EG 8.6✓ Fixed in 2.26.72026-07-29
vulnerable: 1.0.0 ... 2.9.0 (216 versions)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to…
- CVE-2026-67426CRITICALCVSS 9.3EG 9.3✓ Fixed in 2.26.72026-07-29
vulnerable: 1.0.0 ... 2.9.0 (216 versions)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supp…
- CVE-2026-67427HIGHCVSS 8.6EG 8.6✓ Fixed in 2.26.72026-07-29
vulnerable: 1.0.0 ... 2.9.0 (216 versions)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing…
- CVE-2026-67428HIGHCVSS 8.5EG 8.5✓ Fixed in 2.26.72026-07-29
vulnerable: 1.0.0 ... 2.9.0 (216 versions)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graph…
- CVE-2026-67429CRITICALCVSS 10.0EG 10.0✓ Fixed in 2.26.72026-07-29
vulnerable: 1.0.0 ... 2.9.0 (216 versions)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR …
Check whether flyto-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for flyto-core CVEs against the assets you own.
Start Free Scan →