What is CVE-2026-67425?
In Flyto2 Core before version 2.26.6, the `llm.chat` function reads provider keys like OPENAI_API_KEY from the environment and sends them via the Authorization header to an attacker-controlled `base_url`. This allows remote attackers to intercept sensitive API keys. Immediate update to version 2.26.6 or later is strongly recommended.
Azərbaycanca: Flyto2 Core-un 2.26.6-dan əvvəlki versiyalarında, `llm.chat` funksiyası OpenAI və Anthropic kimi provayder açarlarını mühit dəyişənlərindən oxuyaraq hücumçunun idarə etdiyi `base_url`-ə Authorization başlığı ilə göndərir. Bu boşluqdan istifadə edən şəxs uzaqdan həssas API açarlarını ələ keçirə bilər. Dərhal 2.26.6 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Flyto2 Core are affected by CVE-2026-67425?
The vulnerability affects Flyto2 Core versions before 2.26.6.
What data can an attacker obtain by exploiting CVE-2026-67425?
An attacker can intercept sensitive API keys from providers like OpenAI and Anthropic.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.