CVE-2026-67428 is a server-side request forgery vulnerability in Flyto2 Core affecting versions prior to 2.26.7. Multiple HTTP-emitting modules and inline base_url handling paths accepted caller-controlled URLs and issued outbound requests without applying the product’s centralized URL validation mechanism, validate_url_with_env_config. Affected functionality includes HTTP request helpers, GraphQL request paths, monitoring checks, messaging and notification integrations, AI vision-related fetches, visual verification, proxy rotation, and agent or LLM inline URL fetch logic. Because these code paths did not consistently enforce SSRF protections, an authenticated low-privileged user able to configure or trigger workflows could cause the Flyto2 Core server to send requests to loopback addresses, RFC1918 internal services, and cloud metadata endpoints. The issue was fixed in version 2.26.7 by standardizing outbound URL validation across affected modules.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Another SSRF vulnerability in Flyto2 Core mentioned only in the related reports section.
A high-severity SSRF vulnerability in Flyto2 Core prior to 2.26.7 caused by multiple HTTP-emitting modules failing to use centralized URL validation, allowing low-privileged users to access internal endpoints, loopback interfaces, and cloud metadata services.
A server-side request forgery vulnerability in Flyto2 Core where multiple HTTP-capable modules and inline base_url handling fetch caller-controlled URLs without the expected URL validation guard, enabling access to internal or metadata endpoints.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.