Количество 2
Количество 2
CVE-2026-67425
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.6.
GHSA-qq9q-xgm3-xv9g
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-67425 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.6. | CVSS3: 8.6 | 0% Низкий | 8 дней назад | |
GHSA-qq9q-xgm3-xv9g Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url | CVSS3: 8.6 | 0% Низкий | 7 дней назад |
Уязвимостей на страницу