CRITICAL 9.8 CVE-2026-75337 Published 28 Aug 2026

Yu AI Code Mother Path Traversal Vulnerability

Worried this affects one of your servers?

The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal.

User-controlled paths are concatenated to the preview root directory without normalization, allowing anonymous attackers to read files outside the preview root.

Reference: CVE-2026-75337 on NVD

← Back to Security News