File Manipulation Vulnerability in Yutu AI Toolkit by Eat Pray AI
CVE-2026-50158

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-50158?

The Yutu AI Toolkit, developed by Eat Pray AI, has a vulnerability in its caption-download functionality that allows unauthenticated users to execute file manipulation attacks. This occurs because the tool improperly handles user-controlled file paths, enabling potential overwriting of application files, configuration settings, and logs outside its designated root directory. Attackers can use this flaw to achieve unauthorized code execution or service disruptions, notably when the toolkit is running without authentication. The issue has been addressed in version 0.10.9, emphasizing the importance of updating to mitigate these risks.

Affected Version(s)

yutu < 0.10.9-dev1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.