top of page
perceptive_background_267k.jpg

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 20:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Data Breach & Exfiltration, Emerging Technologies

CVE-2026-67427 affects Flyto2 Core, an execution kernel for automation and AI-agent workflows. Prior to version 2.26.6, the workflow engine's variable resolver expands ${env.VAR} for any host environment variable without enforcing an allowlist or capability policy check. This flaw allows a malicious workflow parameter to bypass the default capability policy denylist that governs env.get and env.load_dotenv operations. As a result, attackers can exfiltrate sensitive secrets and environment variables through otherwise permitted modules. The vulnerability represents a policy bypass leading to potential data exfiltration of host secrets. The issue has been patched in version 2.26.6 of Flyto2 Core. Users are advised to upgrade immediately to mitigate the risk of secret exposure.

Technical details

Mitigation steps:

Affected products:

Flyto2 Core

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page