CVE-2026-67425: Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends t...

Added to the CISA Known Exploited Vulnerabilities catalog on 29 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.6.

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to recei...

Required action: Review and patch if applicable to your AI infrastructure.