PT-2026-65896 · Unknown · Flyto2 Core

CVE-2026-67429

·

Published

2026-07-29

·

Updated

2026-08-04

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flyto2 Core versions prior to 2.26.6
Description The image.download and related file-writing modules use a caller-controlled output dir instead of the validate path with env config function and its FLYTO SANDBOX DIR confinement. This allows attacker-controlled response bytes to be written to arbitrary filesystem paths that the process can access.
Recommendations Update to version 2.26.6.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67429
GHSA-2956-977X-2W3R
PYSEC-2026-3568

Affected Products

Flyto2 Core