THREAT OPS › Threat News › [GHSA] GHSA-2956-977x-2w3r (critical) — Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
[GHSA] GHSA-2956-977x-2w3r (critical) — Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
GHSA-2956-977x-2w3r Severity: critical CVE: CVE-2026-67429
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
## Summary
`image.download` fetches a URL and writes the response to disk. It does not use the central path guard (`validate_path_with_env_config`, which confines writes to `FLYTO_SANDBOX_DIR`); instead it confines the output to `output_dir`, but `outp
Indicators of compromise
- CVE-2026-67429cve
Original source: https://github.com/advisories/GHSA-2956-977x-2w3r