CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-67424

CVE-2026-67424: Server-Side Request Forgery Bypass via Unvalidated Redirects in Flyto2 Core

Alon Barad
Alon Barad
Software Engineer

Jul 30, 2026·6 min read·59 visits

Executive Summary (TL;DR)

Flyto2 Core follows HTTP redirects to private internal subnets without revalidating intermediate URLs, leading to an SSRF vulnerability (CVSS 8.5).

An SSRF vulnerability exists in Flyto2 Core due to improper validation of intermediate HTTP redirect hops. While the initial request target is validated against an SSRF protection policy, the HTTP client library (aiohttp) transparently follows 30x redirects to local, internal, or cloud metadata endpoints without application-level revalidation.

Vulnerability Overview

The Flyto2 Core engine is designed to execute automation and artificial intelligence workflows by exposing dynamic orchestration modules. Under normal operational patterns, users utilize modules such as http.get, http.request, and http.batch to retrieve remote resources or execute webhooks. Because these execution runners operate on the internal network boundary of the host system, they expose a highly sensitive network attack surface.

To restrict access to internal infrastructure, the application uses an SSRF guard mechanism named validate_url_with_env_config(url). This validation tool resolves hostnames and asserts that target destinations do not lie within loopback addresses, local network subnets, or metadata addresses. If a user supplies a protected address directly, the application throws an exception and halts execution.

However, a severe design gap exists in how the engine processes downstream network redirections. While the initial request destination undergoes validation, intermediate HTTP redirection targets do not. This vulnerability allows an external, untrusted target to pivot the execution runner into restricted subnets by responding with standard redirection status codes.

Root Cause Analysis

The primary logical failure resides in the configuration of the Python aiohttp HTTP client library used by the request modules. When initializing execution sessions, the application relies on the default network client behavior where the redirect policy is configured with automatic redirection enabled (allow_redirects=True). Consequently, the socket handling layer resolves the redirection at the socket layer without returning control to the parent validation application.

The sequential flaw unfolds when an execution session resolves a public hostname that points to a legitimate external address. The application resolves the target host, verifies it does not match internal IP blocks, and initiates the socket connection. When the external server responds with a redirection status code (such as HTTP 301, 302, 303, 307, or 308) and a Location header, the underlying client immediately executes the subsequent request.

Because the redirection handling occurs transparently within the client library, the application-level validation layer is completely bypassed. If the Location header points to a private loopback target (such as http://127.0.0.1:8500) or cloud instance metadata endpoints (such as http://169.254.169.254/latest/meta-data), the client will establish the socket connection, retrieve the data, and expose internal configuration files or credential secrets.

Code-Level Patch Analysis

The remediation committed in version 2.26.7 focuses on modifying the redirection behavior within src/core/utils.py. The patch explicitly disables automatic redirection on the HTTP client library and replaces it with a manual hop-by-hop checking loop.

# Patched implementation of aiohttp wrapper
_REDIRECT_STATUSES = frozenset({301, 302, 303, 307, 308})
 
async def guarded_aiohttp_request(session, method: str, url: str, *,
                                  max_redirects: int = 5, **kwargs):
    from urllib.parse import urljoin
    # Explicitly remove allow_redirects if passed by the caller
    kwargs.pop('allow_redirects', None)
    guard = ssrf_protection_enabled()
    if guard:
        # Validate the initial URL input
        validate_url_with_env_config(url)
    method = method.upper()
    for hop in range(max_redirects + 1):
        # Execute request with automatic redirection disabled
        response = await session.request(method, url, allow_redirects=False, **kwargs)
        location = response.headers.get('Location')
        
        # Manually intercept redirection status
        if response.status in _REDIRECT_STATUSES and location and hop < max_redirects:
            response.release()  # Prevent connection socket leakage
            url = urljoin(url, location)
            if guard:
                # REVALIDATE EACH INTERMEDIATE HOP AGAINST THE GUARD POLICY
                validate_url_with_env_config(url)
            if response.status == 303:
                method = 'GET'
                kwargs.pop('json', None)
                kwargs.pop('data', None)
            continue
        return response
    return response

By disabling automatic redirects at the library layer via allow_redirects=False, the application intercepts every redirect. The code resolves relative URLs using urljoin and evaluates the resolved URL string against validate_url_with_env_config(url). If any redirect hop target maps to a restricted IP address range, the system raises an SSRFError, terminating the connection.

Exploitation Methodology

An attacker with privileges to configure or trigger a workflow block can exploit this vulnerability to extract confidential credentials from cloud environments. The target runner environment must have access to the internal network space or a cloud metadata endpoint.

To conduct the attack, the adversary registers an external domain and configures it to return redirection response headers pointing to the targeted internal service. For example, a redirect script running on an external server can respond with:

HTTP/1.1 302 Found
Location: http://169.254.169.254/latest/meta-data/iam/security-credentials/admin-role

When the Flyto2 Core engine initiates the execution of the workflow block containing the external URL, the initial validation check resolves the domain to a public IP. The request proceeds, gets redirected, and because of automatic redirect tracking, queries the cloud metadata endpoint, returning the administrative AWS credentials to the attacker inside the workflow output logs.

Security Impact Assessment

The impact of this SSRF bypass is rated high (CVSS v3.1 base score of 8.5). Successful exploitation allows authenticated users with execution privileges to read arbitrary internal configurations, network service responses, database details, and cloud metadata records.

By obtaining access to loopback interfaces, an attacker can exploit other unauthenticated services residing on the local host. For example, local microservices, caches, and queue systems that assume safety within the network perimeter can be read and manipulated. Furthermore, in containerized environments, attackers can pull access tokens belonging to the Kubernetes node or host instance, enabling lateral movement and escalating privileges across the broader cluster deployment.

Remediation & Defensive Measures

The recommended remediation is to immediately update flyto-core to version 2.26.7 or later. This upgrade deploys the custom request handler that manually checks and isolates redirection hops.

In addition to upgrading, security operators should implement host-level network egress restrictions. Restricting runner instances from accessing local subnets (such as 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and blocklisting the cloud metadata address (169.254.169.254) via firewall rules (such as iptables or security groups) establishes a defense-in-depth model that prevents exploitation even in the presence of library-level validation bypasses.

Official Patches

flytohubSecurity fix implementing manual hop checking logic.
flytohubOfficial software update containing the correction.

Fix Analysis (1)

Technical Appendix

CVSS Score
8.5/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
EPSS Probability
0.24%
Top 85% most exploited

Affected Systems

Flyto2 Core execution kernel (flyto-core)

Affected Versions Detail

Product
Affected Versions
Fixed Version
flyto-core
flytohub
< 2.26.72.26.7
AttributeDetail
CWE IDCWE-918
Attack VectorNetwork
CVSS Base Score8.5
EPSS Score0.00236
EPSS Percentile14.80%
Exploit Statuspoc
KEV StatusNot listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
CWE-918
Server-Side Request Forgery (SSRF)

The application constructs an outbound HTTP request using a client-controlled URL destination without proper validation of intermediate redirects, allowing access to private resources.

Known Exploits & Detection

GitHub Security AdvisoryDetails regarding Flyto2 Core redirect SSRF bypass.

Vulnerability Timeline

Security fix committed to version 2.26.7
2026-07-08
Flyto2 Core v2.26.7 officially released
2026-07-08
Advisory published under GHSA-c9hr-64h3-gxpc
2026-07-29
NVD lists the vulnerability under record CVE-2026-67424
2026-07-29

References & Sources

  • [1]GHSA-c9hr-64h3-gxpc: Guarded HTTP modules follow redirects into internal space
  • [2]Flyto Core Hardening Commit
  • [3]NVD - CVE-2026-67424 Detail
Related Vulnerabilities
GHSA-jx74-cqjv-2c67GHSA-pgwh-4jj4-qm8v

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•GHSA-P23F-CM6Q-2QP8
8.6

GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP

SiYuan is an open-source personal knowledge management system. Its Model Context Protocol (MCP) implementation within the asset.upload tool contains a path-traversal and workspace boundary bypass flaw. This allows remote AI models—acting on behalf of attackers via malicious prompts or documents—to import and read sensitive host-system files, such as private keys and system configurations, through absolute path inputs.

Alon Barad
Alon Barad
3 views•6 min read
•about 2 hours ago•GHSA-X8GV-G2G3-65FJ
8.2

CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

An Server-Side Request Forgery (SSRF) vulnerability via DNS-Rebinding Time-of-Check to Time-of-Use (TOCTOU) has been discovered in SiYuan (思源笔记), an open-source personal knowledge management system. The flaw exists within the AI Agent tools http_request (util.HTTPRequest) and web_fetch (util.WebFetch) of the SiYuan Kernel, allowing unauthenticated remote attackers to bypass SSRF validation and access private internal services or cloud metadata endpoints.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 3 hours ago•CVE-2026-104861
7.5

CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

An uncontrolled resource consumption vulnerability (CWE-1333 / CWE-400) exists in probe-image-size versions prior to 7.4.0. The SVG parser utilizes an unanchored, inefficient regular expression to find the SVG root tag, leading to catastrophic backtracking when handling malformed payloads. This blocks the single-threaded Node.js event loop, resulting in a complete denial of service.

Amit Schendel
Amit Schendel
5 views•9 min read
•about 4 hours ago•CVE-2026-10032
6.1

CVE-2026-10032: DOM-based Cross-Site Scripting (XSS) via window.open in Google @a2ui/web_core

CVE-2026-10032 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Google's @a2ui/web_core Node.js library. The vulnerability is located within the openUrl utility function, which processes and opens dynamic URLs defined in layout configurations. Because the function fails to sanitize or validate the target URL scheme before passing it to the window.open browser sink, an attacker can specify a javascript: pseudo-protocol to execute arbitrary client-side script in the context of the host origin.

Amit Schendel
Amit Schendel
7 views•7 min read
•about 5 hours ago•CVE-2026-59944
6.1

CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

CVE-2026-59944 is a path traversal and link-following vulnerability in Composer, the PHP dependency manager. This flaw allows malicious or compromised packages to bypass previous path-hardening protections and perform arbitrary filesystem operations outside of their designated installation directory, leading to unauthorized permission modifications or execution proxy creations.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 6 hours ago•GHSA-QXPP-QJG8-X4JV
9.9

GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.dev

A critical Broken Object Level Authorization (BOLA) vulnerability was identified in Trigger.dev before version v4.5.2. An authenticated attacker could trigger a run replay and supply an arbitrary target environmentId belonging to a completely different tenant. Because the server failed to validate whether the target environment belonged to the same project or organization as the source run, it would execute the task within the victim's environment, resulting in unauthorized cross-tenant write operations and remote task execution.

Alon Barad
Alon Barad
10 views•5 min read