All vulnerabilities CVE-2026-92149 · GHSA-8353-688r-888w yutu: unauthenticated MCP HTTP transport lets any network peer delete videos, playlists and comments highCVSS 8.3 Vendor eat-pray-ai Package github.com/eat-pray-ai/yutu go Affected <= 0.2.0 Credit Avishai Gonen auth-bypassmcp Published advisory