MCPA-2026-0014
Flyto2 Core 2026-07-30 batch: unauthenticated callback SSRF, secret leaks, and guard bypasses (CVE-2026-67424..67428)
Five vulnerabilities in flyto-core before 2.26.7, disclosed together on 2026-07-30: unauthenticated flyto-verification /run callback_url SSRF with internal runner-secret exfiltration (CVE-2026-67426, CVSS 9.3); guarded HTTP modules following redirects into internal address space (CVE-2026-67424); ${env.VAR} interpolation reading arbitrary environment secrets despite an env allowlist (CVE-2026-67427); multiple HTTP-family modules fetching client-controlled URLs without SSRF validation (CVE-2026-67428); and LLM/API keys leaking to an attacker-controlled base_url (CVE-2026-67425). All fixed in 2.26.7.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | flyto-core | >= 0, < 2.26.7 |
Identifiers
CVE-2026-67424CVE-2026-67425CVE-2026-67426CVE-2026-67427CVE-2026-67428GHSA-c9hr-64h3-gxpcGHSA-qq9q-xgm3-xv9gGHSA-jx74-cqjv-2c67GHSA-hr7p-wg7r-hg9mGHSA-pgwh-4jj4-qm8vPYSEC-2026-3569PYSEC-2026-3570PYSEC-2026-3571PYSEC-2026-3572PYSEC-2026-3573CWE-306CWE-522CWE-918
References
- advisory https://github.com/advisories/GHSA-jx74-cqjv-2c67
- advisory https://github.com/advisories/GHSA-c9hr-64h3-gxpc
- advisory https://github.com/advisories/GHSA-qq9q-xgm3-xv9g
- advisory https://github.com/advisories/GHSA-hr7p-wg7r-hg9m
- advisory https://github.com/advisories/GHSA-pgwh-4jj4-qm8v
- web https://nvd.nist.gov/vuln/detail/CVE-2026-67426
Timeline
- Published: 2026-07-30