<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:47:17 +0000</lastBuildDate>
    <item>
      <title>GHSA-h9f9-h6gm-wc85 — flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h9f9-h6gm-wc85</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: flyto-core&lt;/p&gt;
&lt;p&gt;## Unauthenticated Command Execution via HTTP MCP `execute_module`&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-controlled input directly to `asyncio.create_subprocess_shell`. An unauthenticated attacker can execute arbitrary OS commands as the flyto-core server process. By default the server binds to `127.0.0.1`, making this a High-severity local vulnerability (CVSS 8.4); if started with `--host 0.0.0.0`, it becomes remotely exploitable over the network. Dynamic reproduction confirmed command execution as `root` inside a Docker container without any `Authorization` header.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;flyto-core exposes an HTTP API via FastAPI. When the API is started (`flyto serve`), the MCP router is unconditionally mounted at `/mcp` (`src/core/api/server.py:75-78`). The route handler at `src/core/api/routes/mcp.py:65-66` declares `@router.post(&amp;#34;&amp;#34;)` with **no** `Depends(require_auth)` dependency, unlike the analogous REST execution routes (`src/core/api/routes/modules.py:93`) which enforce both authentication and a module denylist.&lt;/p&gt;
&lt;p&gt;The complete unauthenticated data flow from source to sink:&lt;/p&gt;
&lt;p&gt;1. **`src/core/api/server.py:75-78`** — `mcp_router` is mounted under `/mcp` unconditionally at app creation.
2. **`src/core/api/routes/mcp.py:65-66`** — `@router.post(&amp;#34;&amp;#34;)` has no `Depends(require_auth)` guard; any HT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: flyto-core&lt;/p&gt;
&lt;p&gt;## Unauthenticated Command Execution via HTTP MCP `execute_module`&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-controlled input directly to `asyncio.create_subprocess_shell`. An unauthenticated attacker can execute arbitrary OS commands as the flyto-core server process. By default the server binds to `127.0.0.1`, making this a High-severity local vulnerability (CVSS 8.4); if started with `--host 0.0.0.0`, it becomes remotely exploitable over the network. Dynamic reproduction confirmed command execution as `root` inside a Docker container without any `Authorization` header.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;flyto-core exposes an HTTP API via FastAPI. When the API is started (`flyto serve`), the MCP router is unconditionally mounted at `/mcp` (`src/core/api/server.py:75-78`). The route handler at `src/core/api/routes/mcp.py:65-66` declares `@router.post(&amp;#34;&amp;#34;)` with **no** `Depends(require_auth)` dependency, unlike the analogous REST execution routes (`src/core/api/routes/modules.py:93`) which enforce both authentication and a module denylist.&lt;/p&gt;
&lt;p&gt;The complete unauthenticated data flow from source to sink:&lt;/p&gt;
&lt;p&gt;1. **`src/core/api/server.py:75-78`** — `mcp_router` is mounted under `/mcp` unconditionally at app creation.
2. **`src/core/api/routes/mcp.py:65-66`** — `@router.post(&amp;#34;&amp;#34;)` has no `Depends(require_auth)` guard; any HT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h9f9-h6gm-wc85</guid>
    </item>
    <item>
      <title>PYSEC-2026-2482 — flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2482</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: flyto-core&lt;/p&gt;
&lt;p&gt;## Unauthenticated Command Execution via HTTP MCP `execute_module`&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-controlled input directly to `asyncio.create_subprocess_shell`. An unauthenticated attacker can execute arbitrary OS commands as the flyto-core server process. By default the server binds to `127.0.0.1`, making this a High-severity local vulnerability (CVSS 8.4); if started with `--host 0.0.0.0`, it becomes remotely exploitable over the network. Dynamic reproduction confirmed command execution as `root` inside a Docker container without any `Authorization` header.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;flyto-core exposes an HTTP API via FastAPI. When the API is started (`flyto serve`), the MCP router is unconditionally mounted at `/mcp` (`src/core/api/server.py:75-78`). The route handler at `src/core/api/routes/mcp.py:65-66` declares `@router.post(&amp;#34;&amp;#34;)` with **no** `Depends(require_auth)` dependency, unlike the analogous REST execution routes (`src/core/api/routes/modules.py:93`) which enforce both authentication and a module denylist.&lt;/p&gt;
&lt;p&gt;The complete unauthenticated data flow from source to sink:&lt;/p&gt;
&lt;p&gt;1. **`src/core/api/server.py:75-78`** — `mcp_router` is mounted under `/mcp` unconditionally at app creation.
2. **`src/core/api/routes/mcp.py:65-66`** — `@router.post(&amp;#34;&amp;#34;)` has no `Depends(require_auth)` guard; any HT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: flyto-core&lt;/p&gt;
&lt;p&gt;## Unauthenticated Command Execution via HTTP MCP `execute_module`&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-controlled input directly to `asyncio.create_subprocess_shell`. An unauthenticated attacker can execute arbitrary OS commands as the flyto-core server process. By default the server binds to `127.0.0.1`, making this a High-severity local vulnerability (CVSS 8.4); if started with `--host 0.0.0.0`, it becomes remotely exploitable over the network. Dynamic reproduction confirmed command execution as `root` inside a Docker container without any `Authorization` header.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;flyto-core exposes an HTTP API via FastAPI. When the API is started (`flyto serve`), the MCP router is unconditionally mounted at `/mcp` (`src/core/api/server.py:75-78`). The route handler at `src/core/api/routes/mcp.py:65-66` declares `@router.post(&amp;#34;&amp;#34;)` with **no** `Depends(require_auth)` dependency, unlike the analogous REST execution routes (`src/core/api/routes/modules.py:93`) which enforce both authentication and a module denylist.&lt;/p&gt;
&lt;p&gt;The complete unauthenticated data flow from source to sink:&lt;/p&gt;
&lt;p&gt;1. **`src/core/api/server.py:75-78`** — `mcp_router` is mounted under `/mcp` unconditionally at app creation.
2. **`src/core/api/routes/mcp.py:65-66`** — `@router.post(&amp;#34;&amp;#34;)` has no `Depends(require_auth)` guard; any HT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2482</guid>
    </item>
  </channel>
</rss>
