CVE-2026-50158 | eat-pray-ai yutu up to 0.10.9-dev0 caption-download MCP tool pkg/caption/caption.go Caption.Download File path traversal

SecurityVulns

A vulnerability was found in eat-pray-ai yutu up to 0.10.9-dev0. It has been classified as problematic. Affected by this issue is the function Caption.Download of the file pkg/caption/caption.go of the component caption-download MCP tool. Performing a manipulation of the argument File results in path traversal.

This vulnerability is known as CVE-2026-50158. Attacking locally is a requirement. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More