CVE-2026-9473

MEDIUM

c-rick jimeng-mcp api.ts generateVideo path traversal

Title source: cna
STIX 2.1

Description

A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Exploit exploit issue-tracking
https://github.com/c-rick/jimeng-mcp/issues/15
Vdb Entry, Technical Description vdb-entry technical-description
VDB-365454 | c-rick jimeng-mcp api.ts generateVideo path traversal
https://vuldb.com/vuln/365454
Signature, Permissions Required signature permissions-required
VDB-365454 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/365454/cti
Third Party Advisory third-party-advisory
Submit #814003 | c-rick jimeng-mcp dfba9045f07d4bf8601d3e5e28b55e04a8f68970 Path Traversal
https://vuldb.com/submit/814003

Scores

CVSS v3 6.3
EPSS 0.0034
EPSS Percentile 25.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
c-rick/jimeng-mcp 1.10.0
Published May 25, 2026
Tracked Since May 25, 2026