Executive brief
Yu AI Code Mother is an open-source AI code generation platform. An unauthenticated attacker can exploit a path traversal vulnerability in the static resource endpoint to read arbitrary files on the server, including sensitive configuration files, database credentials, and user-generated code outside the intended preview directory.
Technical details
The vulnerability is a path traversal (directory traversal) flaw in the /api/static/{deployKey}/** endpoint of the Spring Boot application. The StaticResourceController directly concatenates user-controlled input (resourcePath from the URL) with the preview root directory without normalizing or validating the path, enabling attackers to traverse parent directories using "../" sequences. No authentication is required; the endpoint lacks the @AuthCheck annotation. An attacker can craft requests like GET /api/static/test_deploy/../../secret.properties to escape the preview root and read sensitive files such as application configuration, database credentials, and temporary files. Embedded Tomcat 10.1 provides partial mitigation by blocking 3+ levels of ".." sequences, but traversal remains possible within that limit and may be bypassed entirely if the application is deployed behind other reverse proxies.
Affected products
- YU AI Code Mother v4.3
Timeline
- 2026-08-28: disclosed