CVE-2026-50158: CWE-73: External Control of File Name or Path in eat-pray-ai yutu
yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg/caption/caption.go, where os.Create() creates or truncates that path without using the pkg.Root confinement boundary backed by YUTU_ROOT. A principal able to invoke caption-download, including a local HTTP client when the MCP server runs with its default authentication-disabled configuration, can write downloaded caption bytes to any path writable by the yutu process outside YUTU_ROOT. This can overwrite application files, configuration, shell startup files, logs, or data and can cause persistent code execution or denial of service depending on the selected writable target. Live caption retrieval also requires usable service credentials and an accessible caption identifier. This issue is fixed in version 0.10.9.
AI Analysis
Technical Summary
The vulnerability in yutu (CVE-2026-50158) involves external control of a file name or path (CWE-73) in the caption-download MCP tool. Prior to version 0.10.9, the tool accepts a file parameter from the caller and passes it to Caption.Download(), which uses os.Create() to create or truncate the file at the specified path. This operation does not enforce confinement within the YUTU_ROOT directory, allowing an attacker with the ability to invoke caption-download to write files anywhere writable by the yutu process. This can overwrite application files, configuration, shell startup files, logs, or data, potentially causing persistent code execution or denial of service. Exploitation requires local HTTP client access to the MCP server (which by default has no authentication) and valid service credentials for live caption retrieval. The vulnerability is addressed in yutu version 0.10.9.
Potential Impact
An attacker able to invoke the caption-download tool can write arbitrary files outside the intended confinement directory, potentially overwriting critical application or system files. This can lead to persistent code execution or denial of service conditions. The vulnerability requires local access to the MCP server and valid service credentials, limiting remote exploitation. No known exploits are reported in the wild.
Mitigation Recommendations
This vulnerability is fixed in yutu version 0.10.9. Users should upgrade to version 0.10.9 or later to remediate the issue. Additionally, enabling authentication on the MCP server can reduce the risk by preventing unauthorized invocation of the caption-download tool.
CVE-2026-50158: CWE-73: External Control of File Name or Path in eat-pray-ai yutu
Description
yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg/caption/caption.go, where os.Create() creates or truncates that path without using the pkg.Root confinement boundary backed by YUTU_ROOT. A principal able to invoke caption-download, including a local HTTP client when the MCP server runs with its default authentication-disabled configuration, can write downloaded caption bytes to any path writable by the yutu process outside YUTU_ROOT. This can overwrite application files, configuration, shell startup files, logs, or data and can cause persistent code execution or denial of service depending on the selected writable target. Live caption retrieval also requires usable service credentials and an accessible caption identifier. This issue is fixed in version 0.10.9.
CVSS v3.1
Score 7.7high
Affected software
eat-pray-ai
yutu
pkg:github/eat-pray-ai/yutuRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in yutu (CVE-2026-50158) involves external control of a file name or path (CWE-73) in the caption-download MCP tool. Prior to version 0.10.9, the tool accepts a file parameter from the caller and passes it to Caption.Download(), which uses os.Create() to create or truncate the file at the specified path. This operation does not enforce confinement within the YUTU_ROOT directory, allowing an attacker with the ability to invoke caption-download to write files anywhere writable by the yutu process. This can overwrite application files, configuration, shell startup files, logs, or data, potentially causing persistent code execution or denial of service. Exploitation requires local HTTP client access to the MCP server (which by default has no authentication) and valid service credentials for live caption retrieval. The vulnerability is addressed in yutu version 0.10.9.
Potential Impact
An attacker able to invoke the caption-download tool can write arbitrary files outside the intended confinement directory, potentially overwriting critical application or system files. This can lead to persistent code execution or denial of service conditions. The vulnerability requires local access to the MCP server and valid service credentials, limiting remote exploitation. No known exploits are reported in the wild.
Mitigation Recommendations
This vulnerability is fixed in yutu version 0.10.9. Users should upgrade to version 0.10.9 or later to remediate the issue. Additionally, enabling authentication on the MCP server can reduce the risk by preventing unauthorized invocation of the caption-download tool.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-03T20:54:20.432Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aac5fee55bf5e2cf5f75523
Added to database: 09/17/2026, 21:47:26 UTC
Last enriched: 09/17/2026, 22:01:46 UTC
Last updated: 09/18/2026, 03:37:04 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.