๐Ÿ” CVE Alert

CVE-2026-108728

MEDIUM 6.5

Flyte 2.0.1 through 2.0.51 Cleartext Secret Exposure via Admission Webhook

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the Pod spec.

CWE CWE-312
Vendor flyteorg
Product flyte
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for flyteorg flyte

Be the first to know when new medium vulnerabilities affecting flyteorg flyte are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

flyteorg / flyte
2.0.1 โ‰ค 2.0.51

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind/flyte-file-secret-pod-spec-disclosure-20261010 github.com: https://github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/flyteplugins/go/tasks/pluginmachinery/secret/embedded_secret_manager.go#L389-L394 github.com: https://github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/flyteplugins/go/tasks/pluginmachinery/secret/embedded_secret_manager.go#L531-L546 github.com: https://github.com/flyteorg/flyte/blob/5986692d3c31d2f2a8a48593219ae6b73644a179/executor/pkg/webhook/handler.go#L168-L189 github.com: https://github.com/flyteorg/flyte vulncheck.com: https://www.vulncheck.com/advisories/flyte-2.0.1-through-2.0.51-cleartext-secret-exposure-via-admission-webhook

Credits

HaiND from the Post and Telecommunication Institute of Technology