Executive brief
A vulnerability in Flyto2 Core allows sensitive API keys for AI services (like OpenAI or Anthropic) to be leaked to unauthorized parties. By providing a custom web address, an attacker can trick the system into sending the administrator's private credentials to a server they control. This could lead to unauthorized usage of AI services, data exposure, and significant financial costs for the account owner.
Technical details
A credential leakage vulnerability exists in Flyto2 Core's LLM and vector database modules, including llm.chat, ai.model, and vector.connector. The application retrieves provider API keys (e.g., OPENAI_API_KEY) from environment variables and automatically attaches them to the 'Authorization' header of outgoing requests. Because the 'base_url' parameter is caller-controlled and only validated against a basic SSRF guard that permits public hosts, an attacker can specify a malicious endpoint to capture the operator's secrets. This occurs because the system fails to verify if the destination host is a trusted provider before attaching sensitive credentials. The issue is fixed in version 2.26.7.
Affected products
- flytohub flyto-core < 2.26.7
Timeline
- 2026-07-07: disclosed
- 2026-07-29: advisory: NVD publication
- 2026-07-30: patched: GitHub Advisory published and reviewed