Impact
The yutu toolkit contains a caption‑download micro‑service that accepts a caller‑controlled file path and writes the downloaded caption data to that path via os.Create(). Because the path is not validated against the YUTU_ROOT confinement boundary, a principal who can invoke the service can overwrite any file or directory that the yutu process can write to. This flaw allows the replacement of application binaries, configuration files, shell startup scripts, logs, or other data, potentially enabling persistent code execution or a denial of service, depending on the chosen target. The service requires a valid service credential and a caption identifier for live caption retrieval, but the vulnerable logic is exercised once those prerequisites are satisfied.
Affected Systems
The vulnerability affects the eat‑pray‑ai:yutu package in all releases prior to version 0.10.9. It is present in the core caption‑download command, which is enabled by default when the MCP server runs without authentication, thereby exposing the endpoint to local or unauthenticated HTTP clients.
Risk and Exploitability
The CVSS score of 7.7 indicates a high‑impact arbitrary file write. The EPSS score of less than 1% suggests that exploitation attempts are expected to be rare as of the current assessment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an HTTP request to the caption‑download endpoint of an MCP server running without authentication; an attacker who also possesses valid credentials and a caption identifier can specify an arbitrary writable path and drive code execution or denial of service.
OpenCVE Enrichment
Github GHSA