CVE-2026-67429

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6.
Configurations

No configuration.

History

29 Jul 2026, 20:17

Type Values Removed Values Added
References () https://github.com/flytohub/flyto-core/security/advisories/GHSA-2956-977x-2w3r - () https://github.com/flytohub/flyto-core/security/advisories/GHSA-2956-977x-2w3r -

29 Jul 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-29 19:16

Updated : 2026-07-30 16:41


NVD link : CVE-2026-67429

Mitre link : CVE-2026-67429

CVE.ORG link : CVE-2026-67429


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path