HIGH
flyteorg
CVE published 2026-10-11
CVE-2026-108728
Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The vulnerability is caused by the embedded secret manager webhook writing base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the P [truncated]