All vulnerabilities

CVE-2026-92149 · GHSA-8353-688r-888w

yutu: unauthenticated MCP HTTP transport lets any network peer delete videos, playlists and comments

highCVSS 8.3
Vendor
eat-pray-ai
Package
github.com/eat-pray-ai/yutu go
Affected
<= 0.2.0
Credit
Avishai Gonen
auth-bypassmcp