Junglewise Threat Intelligence

CVE-2026-67425: Flytohub Flyto2 Core API key leakage via caller-controlled base_url

CVE-2026-67425 · Severity: high · CVSS 8.6 · Published 2026-07-29

Technologies: flyto-core (PyPI). Vendors: PyPI.

Executive brief

A vulnerability in Flyto2 Core allows sensitive API keys for AI services (like OpenAI or Anthropic) to be leaked to unauthorized parties. By providing a custom web address, an attacker can trick the system into sending the administrator's private credentials to a server they control. This could lead to unauthorized usage of AI services, data exposure, and significant financial costs for the account owner.

Technical details

A credential leakage vulnerability exists in Flyto2 Core's LLM and vector database modules, including llm.chat, ai.model, and vector.connector. The application retrieves provider API keys (e.g., OPENAI_API_KEY) from environment variables and automatically attaches them to the 'Authorization' header of outgoing requests. Because the 'base_url' parameter is caller-controlled and only validated against a basic SSRF guard that permits public hosts, an attacker can specify a malicious endpoint to capture the operator's secrets. This occurs because the system fails to verify if the destination host is a trusted provider before attaching sensitive credentials. The issue is fixed in version 2.26.7.

Affected products

  • flytohub flyto-core < 2.26.7

Timeline

  • 2026-07-07: disclosed
  • 2026-07-29: advisory: NVD publication
  • 2026-07-30: patched: GitHub Advisory published and reviewed

References

Related threats