A vulnerability was found in flytohub flyto-core up to 2.26.5. It has been classified as very critical. This affects an unknown function of the component Image Download. Performing a manipulation of the argument output_dir results in improper privilege management.
This vulnerability is cataloged as CVE-2026-67429. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.