Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Vulnerability Description
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Flyto2 Core 路径遍历漏洞
Vulnerability Description
Flyto2 Core是Flyto2组织的一个服务器与网络设备核心平台。 Flyto2 Core 2.26.6之前版本存在安全漏洞,该漏洞源于image.download和相关的写入文件模块使用调用者控制的output_dir而未使用validate_path_with_env_config和FLYTO_SANDBOX_DIR限制,允许攻击者控制的响应字节写入任意文件系统路径。
CVSS Information
N/A
Vulnerability Type
N/A