Vendor
high
advisory
Credential Exfiltration via Unrestricted Base URL in Flyto-core
2 TTPs 1 CVEFlyto-core versions prior to 2.26.7 allow unauthenticated callers to exfiltrate API provider keys by supplying a malicious 'base_url' parameter, which forces the library to append operator-configured secrets to requests sent to attacker-controlled infrastructure.
flyto-core
credential-theft
vulnerability
cloud-security
cve-2026-67425
cve-2026-67427
exfiltration
flyto
variable-interpolation
2t
1c
critical
threat
Unauthenticated SSRF and Secret Exfiltration in Flyto Core
1 rule 4 TTPs 1 CVEAn unauthenticated SSRF vulnerability in the Flyto Core /run endpoint allows attackers to exfiltrate the internal FLYTO_RUNNER_SECRET and perform unauthorized requests against internal infrastructure.
Flyto Core
ssrf
credential-theft
vulnerability
cve-2026-67426
path-traversal
arbitrary-file-write
rce
framework
1r
4t
1c