Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3569
  • PyPI/flyto-core
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation 04 Aug
  • Fix available
  • Severity - 8.5 (High)
PYSEC-2026-3572
  • PyPI/flyto-core
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata) 04 Aug
  • Fix available
  • Severity - 8.5 (High)
PYSEC-2026-3571
  • PyPI/flyto-core
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration 04 Aug
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-3573
  • PyPI/flyto-core
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url 04 Aug
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-3570
  • PyPI/flyto-core
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted 04 Aug
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-3568
  • PyPI/flyto-core
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) 04 Aug
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-c9hr-64h3-gxpc
  • PyPI/flyto-core
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation 30 Jul
  • Fix available
  • Severity - 8.5 (High)
GHSA-pgwh-4jj4-qm8v
  • PyPI/flyto-core
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata) 30 Jul
  • Fix available
  • Severity - 8.5 (High)
GHSA-jx74-cqjv-2c67
  • PyPI/flyto-core
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration 30 Jul
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-qq9q-xgm3-xv9g
  • PyPI/flyto-core
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url 30 Jul
  • Fix available
  • Severity - 8.6 (High)
GHSA-hr7p-wg7r-hg9m
  • PyPI/flyto-core
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted 30 Jul
  • Fix available
  • Severity - 8.6 (High)
GHSA-2956-977x-2w3r
  • PyPI/flyto-core
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) 30 Jul
  • Fix available
  • Severity - 10.0 (Critical)
PYSEC-2026-2482
  • PyPI/flyto-core
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module` 13 Jul
  • Fix available
  • Severity - 8.4 (High)
PYSEC-2026-2481
  • PyPI/flyto-core
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf 13 Jul
  • Fix available
  • Severity - 7.1 (High)
GHSA-h9f9-h6gm-wc85
  • PyPI/flyto-core
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module` 06 Jul
  • Fix available
  • Severity - 8.4 (High)
GHSA-794r-5rp2-fpg8
  • PyPI/flyto-core
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf 06 Jul
  • Fix available
  • Severity - 7.1 (High)