Executive brief
Flyto2 Core, a library used for AI agent operations and document processing, contains a vulnerability that allows an attacker to write files to any location on the server's disk. By bypassing intended security sandboxes, an attacker could overwrite critical system configurations or inject malicious code. This could lead to a complete takeover of the server where the software is running.
Technical details
A path traversal vulnerability exists in Flyto2 Core due to improper path validation in multiple file-writing modules, most notably 'image.download'. While the software attempts to use 'os.path.commonpath' to restrict writes, it allows the caller to provide the 'output_dir' parameter used as the validation base. An attacker can set 'output_dir' to the root directory ('/'), rendering the check ineffective and allowing arbitrary file writes to any location the process has permissions for. Other affected modules include image processing (convert, resize, crop), document generation (excel_write, pdf_fill_form), and browser pagination. This is exploitable via the MCP tool interface or hosted API clients. The vulnerability is patched in version 2.26.7.
Affected products
- flytohub flyto-core < 2.26.7
Timeline
- 2026-07-07: disclosed
- 2026-07-29: kev added: NVD publication date
- 2026-07-30: patched: GitHub Advisory published and reviewed