PatchSiren

flyteorg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH flyteorg CVE published 2026-10-11

CVE-2026-108728

Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The vulnerability is caused by the embedded secret manager webhook writing base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the P [truncated]