Back to list

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration — GHSA-JX74-CQJV-2C67

GitHub · GitHub · GHSA-JX74-CQJV-2C67

ID
GHSA-JX74-CQJV-2C67
Date
Source
GitHub
Vendor
GitHub
Threat
critical

Summary

## Summary The standalone `flyto-verification` service exposes `POST /run` with **no authentication**, on all interfaces (0.0.0.0:8344 per the shipped Dockerfile). The request body's `callback_url` is used verbatim for an outbound POST that **unconditionally attaches `X-Internal-Key: $FLYTO_RUNNER_SECRET`**. The `callback_url` bypasses the service's `target_allowed` allowlist (which only inspects…

Timeline

Published by source
2026-07-30

Risk context

  • Reported severity or threat level: critical.
  • Review exposure for the affected product or family: pip: flyto-core.

Product

pip: flyto-core

What to do

General, cautious steps (verify details in the official source):

  • Prioritize patching or mitigation immediately (treat as actively risky).
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Evidence and provenance

Canonical advisory ID
GHSA-JX74-CQJV-2C67
Source
GitHub
Vendor
GitHub
Published by source
2026-07-30
Last source activity
2026-07-30
Additional identifiers
CVE-2026-67426
Curated by
hlukh.ch

Related advisories and connections

These advisories are connected by shared CVE, product, vendor, source, or time signals.