Yu AI Code Mother v4.3 contains a path traversal vulnerability in its static resource interface at /api/static/{deployKey}/. The user-controlled path parameter is concatenated directly to the preview root directory without any normalization or sanitization. This flaw allows anonymous, unauthenticated attackers to read arbitrary files outside the intended preview root directory. The vulnerability requires no authentication, significantly raising its risk profile. A proof-of-concept has been published on GitHub demonstrating exploitation. The issue is tracked as CVE-2026-75337 and reported via NVD.