An Unauthenticated MCP Call Could Run Commands as flyto-core
The flyto-core repository advisory, dated 30 May 2026, says unauthenticated HTTP POST /mcp calls could reach a shell module; an analogous REST execution route required authentication. Versions 2.26.2 to before 2.26.4 are affected; 2.26.4 is fixed. Default loopback binding limits reach unless changed. Commands inherit server-process privileges. A root-in-container demonstration proves neither host-root access nor malicious exploitation.
For CVE-2026-55786, use the repository advisory because BlackTree’s report is unavailable. The October database update is not a new disclosure.
Verify the actual boundary
BlackTree analysis: Record the deployed version, listener address, port mapping and process identity, including developer workstations. These facts bound exposure.
Upgrade to 2.26.4 or later. In a safe test, verify an unauthenticated call cannot invoke the tool. Record the result. Where exposed, review host evidence before drawing conclusions; missing alerts do not prove absence of compromise.
BlackTree’s Chainlit MCP report concerns another product. Give each tool endpoint its own access decision.


