PT-2026-65894 · Unknown · Flyto2 Core

CVE-2026-67427

·

Published

2026-07-29

·

Updated

2026-08-04

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flyto2 Core versions prior to 2.26.6
Description The workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check. This allows a workflow parameter to bypass the default capability policy denylist for env.get() and env.load dotenv() functions, potentially leading to the exfiltration of secrets through allowed modules.
Recommendations Update to version 2.26.6.

Exploit

Fix

Insufficiently Protected Credentials

Protection Mechanism Failure

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67427
GHSA-HR7P-WG7R-HG9M
PYSEC-2026-3570

Affected Products

Flyto2 Core