CVE-2026-75337

The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 00:18

Updated : 2026-09-09 16:04


NVD link : CVE-2026-75337

Mitre link : CVE-2026-75337

CVE.ORG link : CVE-2026-75337


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')