Description
yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg/caption/caption.go, where os.Create() creates or truncates that path without using the pkg.Root confinement boundary backed by YUTU_ROOT. A principal able to invoke caption-download, including a local HTTP client when the MCP server runs with its default authentication-disabled configuration, can write downloaded caption bytes to any path writable by the yutu process outside YUTU_ROOT. This can overwrite application files, configuration, shell startup files, logs, or data and can cause persistent code execution or denial of service depending on the selected writable target. Live caption retrieval also requires usable service credentials and an accessible caption identifier. This issue is fixed in version 0.10.9.
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write leading to Potential Code Execution
Action: Immediate Patch
AI Analysis

Impact

The yutu toolkit contains a caption‑download micro‑service that accepts a caller‑controlled file path and writes the downloaded caption data to that path via os.Create(). Because the path is not validated against the YUTU_ROOT confinement boundary, a principal who can invoke the service can overwrite any file or directory that the yutu process can write to. This flaw allows the replacement of application binaries, configuration files, shell startup scripts, logs, or other data, potentially enabling persistent code execution or a denial of service, depending on the chosen target. The service requires a valid service credential and a caption identifier for live caption retrieval, but the vulnerable logic is exercised once those prerequisites are satisfied.

Affected Systems

The vulnerability affects the eat‑pray‑ai:yutu package in all releases prior to version 0.10.9. It is present in the core caption‑download command, which is enabled by default when the MCP server runs without authentication, thereby exposing the endpoint to local or unauthenticated HTTP clients.

Risk and Exploitability

The CVSS score of 7.7 indicates a high‑impact arbitrary file write. The EPSS score of less than 1% suggests that exploitation attempts are expected to be rare as of the current assessment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an HTTP request to the caption‑download endpoint of an MCP server running without authentication; an attacker who also possesses valid credentials and a caption identifier can specify an arbitrary writable path and drive code execution or denial of service.

Generated by OpenCVE AI on September 19, 2026 at 01:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade yutu to version 0.10.9 or newer, which removes the vulnerable file‑write logic.
  • If an immediate update is not possible, enable authentication on the MCP server or limit network access so that only trusted local hosts can reach the caption‑download endpoint.
  • Configure the YUTU_ROOT environment variable to point to a secure directory with no world‑writable permissions and run the yutu process with the least privileges required for normal operation.

Generated by OpenCVE AI on September 19, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2c7f-fxww-6w6c yutu: Arbitrary File Write via MCP `caption-download` Tool
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Eat-pray-ai
Eat-pray-ai yutu
Vendors & Products Eat-pray-ai
Eat-pray-ai yutu

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg/caption/caption.go, where os.Create() creates or truncates that path without using the pkg.Root confinement boundary backed by YUTU_ROOT. A principal able to invoke caption-download, including a local HTTP client when the MCP server runs with its default authentication-disabled configuration, can write downloaded caption bytes to any path writable by the yutu process outside YUTU_ROOT. This can overwrite application files, configuration, shell startup files, logs, or data and can cause persistent code execution or denial of service depending on the selected writable target. Live caption retrieval also requires usable service credentials and an accessible caption identifier. This issue is fixed in version 0.10.9.
Title yutu: Arbitrary File Write via MCP `caption-download` Tool
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Eat-pray-ai Yutu
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T14:43:19.020Z

Reserved: 2026-06-03T20:54:20.432Z

Link: CVE-2026-50158

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:16:59.297

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-50158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:00:13Z

Weaknesses
  • CWE-73

    External Control of File Name or Path