Missing Authentication for Critical Function Affecting flyto-core package, versions [2.26.2,2.26.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authentication for Critical Function vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-FLYTOCORE-17824488
  • published6 Jul 2026
  • disclosed6 Jul 2026
  • creditUnknown

Introduced: 6 Jul 2026

CVE-2026-55786  (opens in a new tab)
CWE-306  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade flyto-core to version 2.26.4 or higher.

Overview

flyto-core is an A workflow engine with 412 built-in modules. Trace every step. Replay from any point.

Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the execute_module process. An attacker can execute arbitrary operating system commands with the privileges of the server process by sending specially crafted unauthenticated HTTP requests to the /mcp endpoint, which dispatches attacker-controlled input to asyncio.create_subprocess_shell without authentication or input sanitization. This is only exploitable if the server is accessible to the attacker, such as when it is bound to a non-loopback interface or the attacker has local access.

CVSS Base Scores

version 4.0
version 3.1