{"data":{"id":"9841f83f-99d7-473b-b768-299517b657a1","title":"CVE-2026-67428: Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi","summary":"Flyto2 Core, a system that runs automation and AI agent workflows, had a security flaw in versions before 2.26.7 where multiple modules that send HTTP requests did not properly validate URLs, allowing SSRF (server-side request forgery, where an attacker tricks the system into making requests to internal or private endpoints it shouldn't access).","solution":"Update to version 2.26.7, which fixes this issue.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67428","publishedAt":"2026-07-29T19:16:52.087Z","cveId":"CVE-2026-67428","cweIds":["CWE-918"],"cvssScore":"8.5","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Flyto2"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-29T19:16:52.087Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}