CVE-2026-67427 | flytohub flyto-core up to 2.26.5 Workflow Engine Variable Resolver env.get/env.load_dotenv workflow parameter permission assignment
A vulnerability was found in flytohub flyto-core up to 2.26.5 and classified as problematic. The impacted element is the function env.get/env.load_dotenv of the component Workflow Engine Variable Resolver. Such manipulation of the argument workflow parameter leads to incorrect permission assignment.
This vulnerability is listed as CVE-2026-67427. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More