Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration — GHSA-JX74-CQJV-2C67
GitHub · GitHub · GHSA-JX74-CQJV-2C67
ID
GHSA-JX74-CQJV-2C67
GHSA-JX74-CQJV-2C67
Date
Source
GitHub
GitHub
Vendor
GitHub
GitHub
Threat
critical
critical
Summary
## Summary The standalone `flyto-verification` service exposes `POST /run` with **no authentication**, on all interfaces (0.0.0.0:8344 per the shipped Dockerfile). The request body's `callback_url` is used verbatim for an outbound POST that **unconditionally attaches `X-Internal-Key: $FLYTO_RUNNER_SECRET`**. The `callback_url` bypasses the service's `target_allowed` allowlist (which only inspects…
Timeline
- Published by source
- 2026-07-30
Risk context
- Reported severity or threat level: critical.
- Review exposure for the affected product or family: pip: flyto-core.
Product
pip: flyto-core
What to do
General, cautious steps (verify details in the official source):
- Prioritize patching or mitigation immediately (treat as actively risky).
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.
Official advisory
Evidence and provenance
- Canonical advisory ID
- GHSA-JX74-CQJV-2C67
- Source
- GitHub
- Vendor
- GitHub
- Published by source
- 2026-07-30
- Last source activity
- 2026-07-30
- Additional identifiers
- CVE-2026-67426
- Curated by
- hlukh.ch
Related advisories and connections
These advisories are connected by shared CVE, product, vendor, source, or time signals.