THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hr7p-wg7r-hg9m (high) — Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

[GHSA] GHSA-hr7p-wg7r-hg9m (high) — Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

highgithub_advisoriesPublished 2026-07-30

GHSA-hr7p-wg7r-hg9m Severity: high CVE: CVE-2026-67427

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

## Summary

The capability policy denies the `env.get` and `env.load_dotenv` modules by default, with the stated reason that they read arbitrary host environment variables (API keys, DSNs) and are a secret-exfil risk. But the workflow engine's variabl

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hr7p-wg7r-hg9m