CVE-2026-75337

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root.

Published 2026-08-28. Last modified 2026-09-09.