VulnSea

flyto-core has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 8. The median CVSS is 8.6 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-918 (4) and CWE-522 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.6
Publish → KEV
Last 90 days
8 prev 0

Products

  • flyto-core 8
8
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

flyto-core vulnerabilities

CVEs affecting flyto-core, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-67429Critical· 10.0
1mo ago

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Midnightflyto-core · flyto-coreEPSS 0.49%via GHSA
CVE-2026-67427High· 8.6
1mo ago

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Twilightflyto-core · flyto-coreEPSS 0.36%via GHSA
CVE-2026-67425High· 8.6
1mo ago

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Twilightflyto-core · flyto-coreEPSS 0.32%via GHSA
CVE-2026-67426Critical· 9.3
1mo ago

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Midnightflyto-core · flyto-coreEPSS 0.31%via GHSA
CVE-2026-67428High· 8.5
1mo ago

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Twilightflyto-core · flyto-coreEPSS 0.34%via GHSA
CVE-2026-67424High· 8.5
1mo ago

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Twilightflyto-core · flyto-coreEPSS 0.24%via GHSA
CVE-2026-55787High· 7.1
2mo ago

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

Twilightflyto-core · flyto-corevia GHSA
CVE-2026-55786High· 8.4
2mo ago

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

Twilightflyto-core · flyto-corevia GHSA
flyto-core vulnerabilities (CVEs) · VulnSea