{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/flyto-core--2.26.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-67425"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["flyto-core (\u003c 2.26.7)"],"_cs_severities":["high"],"_cs_tags":["credential-theft","vulnerability","cloud-security","cve-2026-67425","cve-2026-67427","exfiltration","flyto","variable-interpolation"],"_cs_type":"advisory","_cs_vendors":["Flyto"],"content_html":"\u003cp\u003eFlyto-core is susceptible to a credential exfiltration vulnerability (CVE-2026-67425) affecting multiple modules including \u003ccode\u003ellm.chat\u003c/code\u003e, \u003ccode\u003eai.model\u003c/code\u003e, \u003ccode\u003ellm.agent\u003c/code\u003e, and \u003ccode\u003evector.connector\u003c/code\u003e. The vulnerability exists because the library automatically fetches sensitive environment variables, such as \u003ccode\u003eOPENAI_API_KEY\u003c/code\u003e or \u003ccode\u003eQDRANT_API_KEY\u003c/code\u003e, and appends them as \u003ccode\u003eAuthorization: Bearer\u003c/code\u003e headers to outgoing HTTP requests. While the library implements an SSRF guard, this mechanism only validates that the target host is not private; it does not prevent the application from sending requests to public, attacker-controlled servers. An attacker capable of influencing the \u003ccode\u003ebase_url\u003c/code\u003e parameter via the MCP agent surface or hosted API can redirect these requests to an arbitrary public endpoint, successfully capturing the operator's environment-stored credentials. This vulnerability affects all \u003ccode\u003eflyto-core\u003c/code\u003e versions prior to 2.26.7 and can result in significant financial and data impact through unauthorized account usage.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an exposed application interface that interacts with \u003ccode\u003eflyto-core\u003c/code\u003e and allows user-supplied parameters.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a payload specifically targeting the \u003ccode\u003ebase_url\u003c/code\u003e parameter within the library's \u003ccode\u003ellm.chat\u003c/code\u003e or \u003ccode\u003eai.model\u003c/code\u003e functions.\u003c/li\u003e\n\u003cli\u003eAttacker points \u003ccode\u003ebase_url\u003c/code\u003e to a custom-controlled public web server capable of capturing inbound HTTP headers.\u003c/li\u003e\n\u003cli\u003eThe victim application receives the malicious request and passes the \u003ccode\u003ebase_url\u003c/code\u003e parameter to the vulnerable library functions.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eflyto-core\u003c/code\u003e performs an SSRF check, which validates that the attacker's public URL is not a private IP, allowing the request to proceed.\u003c/li\u003e\n\u003cli\u003eThe library retrieves the operator's secret key from environment variables (e.g., \u003ccode\u003eOPENAI_API_KEY\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe library transmits a POST request to the attacker's server, attaching the secret key in the \u003ccode\u003eAuthorization: Bearer\u003c/code\u003e header.\u003c/li\u003e\n\u003cli\u003eAttacker logs the incoming request, extracts the Bearer token, and uses it to perform unauthorized API calls on behalf of the victim.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the exfiltration of high-privilege cloud LLM and vector database credentials. Attackers can leverage these keys to incur fraudulent billing costs, exfiltrate sensitive data accessible to the LLM or vector store, or manipulate internal AI workflows. The ease of triggering this via the library's exposed API surfaces makes this a critical risk for any organization utilizing vulnerable versions of \u003ccode\u003eflyto-core\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003eflyto-core\u003c/code\u003e to version 2.26.7 or higher immediately to apply the vendor-supplied patches (CVE-2026-67425).\u003c/li\u003e\n\u003cli\u003eAudit application code to identify all calls to \u003ccode\u003ellm.chat\u003c/code\u003e, \u003ccode\u003eai.model\u003c/code\u003e, \u003ccode\u003ellm.agent\u003c/code\u003e, and \u003ccode\u003evector.connector\u003c/code\u003e where user-controlled input influences the \u003ccode\u003ebase_url\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eImplement strict allowlisting for allowed API endpoints rather than relying on SSRF guards for credential-handling components.\u003c/li\u003e\n\u003cli\u003eRotate any API keys that were potentially exposed in environment variables if the application was reachable by untrusted actors.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T15:29:38Z","date_published":"2026-07-30T15:29:30Z","id":"https://feed.craftedsignal.io/briefs/2026-07-flyto-core-leak/","summary":"Flyto-core versions prior to 2.26.7 allow unauthenticated callers to exfiltrate API provider keys by supplying a malicious 'base_url' parameter, which forces the library to append operator-configured secrets to requests sent to attacker-controlled infrastructure.","title":"Credential Exfiltration via Unrestricted Base URL in Flyto-core","url":"https://feed.craftedsignal.io/briefs/2026-07-flyto-core-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Flyto-Core (\u003c 2.26.7)","version":"https://jsonfeed.org/version/1.1"}