


Perceptive Security
SOC/SIEM Consultancy

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/m…
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 20:03:55
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies, Enterprise Applications
CVE-2026-67424 affects Flyto2 Core, an execution kernel for automation and AI-agent workflows. Versions prior to 2.26.7 contain an SSRF (Server-Side Request Forgery) vulnerability in the HTTP modules http.get, http.request, and http.batch. The flaw exists because only the initial URL is validated, while subsequent redirects are followed without per-hop Location header revalidation. This allows an attacker to craft a public URL that redirects into internal address space, potentially exposing internal services and their response bodies. The affected files are get.py, request.py, and batch.py within the atomic HTTP module path. The vulnerability has been patched in version 2.26.7. Fixes are available via the official GitHub release and commit. This issue is particularly concerning in AI-agent and automation workflow contexts where HTTP modules may be invoked with attacker-influenced URLs.
Technical details
Mitigation steps:
Affected products:
Flyto2 Core
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67424
https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9
https://github.com/flytohub/flyto-core/releases/tag/v2.26.7
https://github.com/flytohub/flyto-core/security/advisories/GHSA-c9hr-64h3-gxpc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
