PT-2026-65892 · Unknown · Flyto2 Core

CVE-2026-67425

·

Published

2026-07-29

·

Updated

2026-08-04

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flyto2 Core versions prior to 2.26.6
Description The llm.chat function reads provider keys, such as OPENAI API KEY and ANTHROPIC API KEY, from the environment and transmits them within the Authorization: Bearer header to a base url controlled by the caller. This allows an attacker to capture the operator's keys on a public host that bypasses the SSRF (Server-Side Request Forgery) guard, which is a vulnerability where a server is tricked into making requests to an unintended location.
Recommendations Update to version 2.26.6.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67425
GHSA-QQ9Q-XGM3-XV9G
PYSEC-2026-3573

Affected Products

Flyto2 Core