Количество 2
Количество 2
CVE-2026-67429
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6.
GHSA-2956-977x-2w3r
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-67429 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6. | CVSS3: 10 | 0% Низкий | 3 дня назад | |
GHSA-2956-977x-2w3r Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) | CVSS3: 10 | 0% Низкий | 1 день назад |
Уязвимостей на страницу