flyto-core vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-67424Highflyto-core: Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationCVE-2026-67428Highflyto-core: Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to…CVE-2026-67426Criticalflyto-core: Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationCVE-2026-67425Highflyto-core: Flyto2 Core: LLM/API keys leak to an attacker-controlled base_urlCVE-2026-67427Highflyto-core: Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedCVE-2026-67429Criticalflyto-core: Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)CVE-2026-55786Highflyto-core: flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`CVE-2026-55787Highflyto-core: flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

Stop the waste.
Protect your environment with Kodem.