top of page
perceptive_background_267k.jpg

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/m…

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 20:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Emerging Technologies, Enterprise Applications

CVE-2026-67424 affects Flyto2 Core, an execution kernel for automation and AI-agent workflows. Versions prior to 2.26.7 contain an SSRF (Server-Side Request Forgery) vulnerability in the HTTP modules http.get, http.request, and http.batch. The flaw exists because only the initial URL is validated, while subsequent redirects are followed without per-hop Location header revalidation. This allows an attacker to craft a public URL that redirects into internal address space, potentially exposing internal services and their response bodies. The affected files are get.py, request.py, and batch.py within the atomic HTTP module path. The vulnerability has been patched in version 2.26.7. Fixes are available via the official GitHub release and commit. This issue is particularly concerning in AI-agent and automation workflow contexts where HTTP modules may be invoked with attacker-influenced URLs.

Technical details

Mitigation steps:

Affected products:

Flyto2 Core

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page