VYPR

yutu

by Yutu

CVEs (1)

  • CVE-2026-50158higJul 14, 2026
    risk 0.45cvss epss

    ## Arbitrary File Write via MCP `caption-download` Tool ### Summary The `caption-download` MCP tool in yutu passes the caller-supplied `file` parameter directly to `os.Create()` at `pkg/caption/caption.go:272` without any path validation, canonicalization, or confinement to…