


Perceptive Security
SOC/SIEM Consultancy

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 20:03:55
Source:
nvd.nist.gov
Emerging Technologies, Identity & Access, Data Breach & Exfiltration, Web Technologies
CVE-2026-67425 affects Flyto2 Core, an execution kernel for automation and AI-agent workflows. Prior to version 2.26.6, the llm.chat function reads LLM provider API keys (such as OPENAI_API_KEY and ANTHROPIC_API_KEY) from the environment and forwards them in Authorization: Bearer headers to a caller-controlled base_url. An attacker can exploit this by supplying a malicious base_url that bypasses the SSRF guard, causing the application to send the operator's API keys to an attacker-controlled host. This constitutes a credential exfiltration vulnerability with significant impact on confidentiality and potential financial abuse of stolen API keys. The vulnerability has been patched in version 2.26.6. Users are strongly advised to upgrade immediately and rotate any potentially exposed API keys.
Technical details
Mitigation steps:
Affected products:
Flyto2 Core
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67425
https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc
https://github.com/flytohub/flyto-core/releases/tag/v2.26.6
https://github.com/flytohub/flyto-core/security/advisories/GHSA-qq9q-xgm3-xv9g
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
