以下是该漏洞描述的中文翻译: Yutu 是一款由 AI 驱动的 YouTube 频道管理与增长工具包。在 0.10.9 版本之前, MCP 工具通过 接受由调用方控制的 参数,并将其传递给 中的 函数。在该函数中, 会在未使用由 支持的 约束边界的情况下,创建或截断该路径对应的文件。 任何能够调用 的主体——包括在 MCP 服务器以默认配置运行(即未启用身份验证)时的本地 HTTP 客户端——都可以将下载的caption字节写入 之外、且可被 yutu 进程写入的任意路径。这可能会覆盖应用程序文件、配置文件、She
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| eat-pray-ai | yutu | < 0.10.9-dev1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet