CRITICAL
9.8 CVE-2026-75337 Published 28 Aug 2026
Yu AI Code Mother Path Traversal Vulnerability
Worried this affects one of your servers?
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal.
User-controlled paths are concatenated to the preview root directory without normalization, allowing anonymous attackers to read files outside the preview root.
Reference: CVE-2026-75337 on NVD
← Back to Security News