CVE Tracker

CVE-2026-67429 @ mufasa

Status
does_not_affect
Priority
8.12
Match score
2.5
Risk
Other
CVSS
10.0 CRITICAL
Reason
packages: filesystem
Created
2026-08-02T02:51:22Z
Updated
2026-08-02T08:40:22Z
Closed
2026-08-02T08:40:22Z

Package interrogation (copy)

Run on the host — click to copy a command. RPM

PackageCommands
filesystem

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Suggestions: filesystem

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-45661 9.9 morris, mufasa does_not_affect filesystem
CVE-2026-68770 9.8 morris, mufasa does_not_affect filesystem
CVE-2025-40212 9.8 morris, mufasa not_applicable filesystem
CVE-2026-36829 9.8 morris, mufasa does_not_affect filesystem
CVE-2026-25879 9.8 morris, mufasa does_not_affect filesystem
CVE-2026-47162 8.8 Archive, Janus, Library, Matrix, Saiph accepted_risk filesystem
CVE-2023-4692 7.5 Archive, Janus, Library, Saiph, morris accepted_risk, fixed filesystem

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
CloudLinux release 7.9 (Boris Yegorov) (7.9) · cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64
kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
morris does_not_affect 8.12 2026-08-02T08:40:10Z Open

Description

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6.

Determination

Product not installed

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-02T08:40:22Z — does_not_affect
Product not installed

References

NVD: CVE-2026-67429