CVE-2026-67429
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled outputdir instead of validatepathwithenvconfig and its FLYTOSANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/flytohub/flyto-core/releases/tag/v2.26.6, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67429.json, https://github.com/flytohub/flyto-core/security/advisories/GHSA-2956-977x-2w3r, https://nvd.nist.gov/vuln/detail/CVE-2026-67429, https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc