MCPA-2026-0008
criticalpath-traversalCVSS 10
Flyto2 Core arbitrary file write via image.download output_dir bypass (CVE-2026-67429)
flyto-core (a PyPI MCP-native AI agent execution engine) versions before 2.26.7 let callers of the image.download module set both output_path and the output_dir base it is validated against, so the path-confinement check is meaningless: attacker-controlled HTTP response bytes can be written to any absolute path the process can write. Rated CVSS 10.0 (scope-changed integrity/availability impact). Fixed in 2.26.7.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | flyto-core | >= 0, < 2.26.7 |
Identifiers
CVE-2026-67429GHSA-2956-977x-2w3rPYSEC-2026-3568CWE-22
References
- advisory https://github.com/advisories/GHSA-2956-977x-2w3r
- advisory https://github.com/flytohub/flyto-core/security/advisories/GHSA-2956-977x-2w3r
- fix https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc
- web https://nvd.nist.gov/vuln/detail/CVE-2026-67429
Timeline
- Published: 2026-07-30