CVE-2026-108728
Flyte 2.0.1 through 2.0.51 Cleartext Secret Exposure via Admission Webhook
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the Pod spec.
| CWE | CWE-312 |
| Vendor | flyteorg |
| Product | flyte |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for flyteorg flyte
Be the first to know when new medium vulnerabilities affecting flyteorg flyte are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
flyteorg / flyte
2.0.1 โค 2.0.51
References
hackmd.io: https://hackmd.io/@haind/flyte-file-secret-pod-spec-disclosure-20261010 github.com: https://github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/flyteplugins/go/tasks/pluginmachinery/secret/embedded_secret_manager.go#L389-L394 github.com: https://github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/flyteplugins/go/tasks/pluginmachinery/secret/embedded_secret_manager.go#L531-L546 github.com: https://github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/executor/pkg/webhook/handler.go#L168-L189 github.com: https://github.com/flyteorg/flyte vulncheck.com: https://www.vulncheck.com/advisories/flyte-2.0.1-through-2.0.51-cleartext-secret-exposure-via-admission-webhook
Credits
HaiND from the Post and Telecommunication Institute of Technology